Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 515
Alerts This Week
Warning Icon 1 515

Ubuntu: USN-1786-1 Critical: Firefox Denial Of Service Exploit

ubuntu
Calendar Grey April 4, 2013
Scroller Ubuntu
Various security flaws in Firefox could enable malicious actors to cause the application to crash or run arbitrary code under the user's context. Ensure your system is updated.
Firefox could be made to crash or run programs as your login if it opened a malicious website.

Summary

Firefox could be made to crash or run programs as your login if it

opened a malicious website.

Software Description:

- firefox: Mozilla Open Source web browser

Details:

Olli Pettay, Jesse Ruderman, Boris Zbarsky, Christian Holler, Milan

Sreckovic, Joe Drew, Andrew McCreight, Randell Jesup, Gary Kwong and

Mats Palmgren discovered multiple memory safety issues affecting Firefox.

If the user were tricked into opening a specially crafted page, an

attacker could possibly exploit these to cause a denial of service via

application crash, or potentially execute code with the privileges of the

user invoking Firefox. (CVE-2013-0788, CVE-2013-0789)

Ambroz Bizjak discovered an out-of-bounds array read in the

CERT_DecodeCertPackage function of the Network Security Services (NSS)

libary when decoding certain certificates. An attacker could potentially

exploit this to cause a denial of service via application crash.

(CVE-2013-0791)

Tobias Schula discovered an informati...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 12.10:
  firefox                         20.0+build1-0ubuntu0.12.10.3

Ubuntu 12.04 LTS:
  firefox                         20.0+build1-0ubuntu0.12.04.3

Ubuntu 11.10:
  firefox                         20.0+build1-0ubuntu0.11.10.3

Ubuntu 10.04 LTS:
  firefox                         20.0+build1-0ubuntu0.10.04.3

After a standard system update you need to restart Firefox to make
all the necessary changes.

References

https://ubuntu.com/security/notices/USN-1786-1

CVE-2013-0788, CVE-2013-0789, CVE-2013-0791, CVE-2013-0792,

CVE-2013-0793, CVE-2013-0794, CVE-2013-0795, CVE-2013-0796,

CVE-2013-0800, https://bugs.launchpad.net/ubuntu/+source/firefox/+bug/1161422

Severity
critical
Lowest
Low
Medium
High
Critical

April 04, 2013

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.