Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 510
Alerts This Week
Warning Icon 1 510

Ubuntu 13.04: USN-1822-1 Moderate Firefox Memory Safety Exploits

ubuntu
Calendar Grey May 14, 2013
Scroller Ubuntu
Explore key security concerns for Ubuntu users of Firefox, highlighting vulnerabilities, critical updates, and essential preventive measures to enhance protection
Firefox could be made to crash or run programs as your login if it opened a malicious website.

Summary

Firefox could be made to crash or run programs as your login if it

opened a malicious website.

Software Description:

- firefox: Mozilla Open Source web browser

Details:

Multiple memory safety issues were discovered in Firefox. If the user were

tricked into opening a specially crafted page, an attacker could possibly

exploit these to cause a denial of service via application crash, or

potentially execute code with the privileges of the user invoking Firefox.

(CVE-2013-0801, CVE-2013-1669)

Cody Crews discovered that some constructors could be used to bypass

restrictions enforced by their Chrome Object Wrapper (COW). An attacker

could exploit this to conduct cross-site scripting (XSS) attacks.

(CVE-2013-1670)

It was discovered that the file input element could expose the full local

path under certain conditions. An attacker could potentially exploit this

to steal sensitive information. (CVE-2013-1671)

A use-after-free was discovered when resizing video co...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 13.04:
  firefox                         21.0+build2-0ubuntu0.13.04.2

Ubuntu 12.10:
  firefox                         21.0+build2-0ubuntu0.12.10.2

Ubuntu 12.04 LTS:
  firefox                         21.0+build2-0ubuntu0.12.04.3

After a standard system update you need to restart Firefox to make
all the necessary changes.

References

https://ubuntu.com/security/notices/USN-1822-1

CVE-2013-0801, CVE-2013-1669, CVE-2013-1670, CVE-2013-1671,

CVE-2013-1674, CVE-2013-1675, CVE-2013-1676, CVE-2013-1677,

CVE-2013-1678, CVE-2013-1679, CVE-2013-1680, CVE-2013-1681,

https://bugs.launchpad.net/ubuntu/+source/firefox/+bug/1178277

May 14, 2013

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.