Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
Firefox could be made to crash or run programs as your login if it
opened a malicious website.
Software Description:
- firefox: Mozilla Open Source web browser
Details:
Olli Pettay, Jesse Ruderman, Boris Zbarsky, Christian Holler, Milan
Sreckovic, Joe Drew, Andrew McCreight, Randell Jesup, Gary Kwong and
Mats Palmgren discovered multiple memory safety issues affecting Firefox.
If the user were tricked into opening a specially crafted page, an
attacker could possibly exploit these to cause a denial of service via
application crash, or potentially execute code with the privileges of the
user invoking Firefox. (CVE-2013-0788, CVE-2013-0789)
Ambroz Bizjak discovered an out-of-bounds array read in the
CERT_DecodeCertPackage function of the Network Security Services (NSS)
libary when decoding certain certificates. An attacker could potentially
exploit this to cause a denial of service via application crash.
(CVE-2013-0791)
Tobias Schula discovered an informati...
The problem can be corrected by updating your system to the following package versions: Ubuntu 12.10: firefox 20.0+build1-0ubuntu0.12.10.3 Ubuntu 12.04 LTS: firefox 20.0+build1-0ubuntu0.12.04.3 Ubuntu 11.10: firefox 20.0+build1-0ubuntu0.11.10.3 Ubuntu 10.04 LTS: firefox 20.0+build1-0ubuntu0.10.04.3 After a standard system update you need to restart Firefox to make all the necessary changes.
https://ubuntu.com/security/notices/USN-1786-1
CVE-2013-0788, CVE-2013-0789, CVE-2013-0791, CVE-2013-0792,
CVE-2013-0793, CVE-2013-0794, CVE-2013-0795, CVE-2013-0796,
CVE-2013-0800, https://bugs.launchpad.net/ubuntu/+source/firefox/+bug/1161422
Get the latest Linux and open source security news straight to your inbox.