Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
Firefox could be made to crash or run programs as your login if it
opened a malicious website.
Software Description:
- firefox: Mozilla Open Source web browser
Details:
Multiple memory safety issues were discovered in Firefox. If the user were
tricked into opening a specially crafted page, an attacker could possibly
exploit these to cause a denial of service via application crash, or
potentially execute code with the privileges of the user invoking Firefox.
(CVE-2013-0801, CVE-2013-1669)
Cody Crews discovered that some constructors could be used to bypass
restrictions enforced by their Chrome Object Wrapper (COW). An attacker
could exploit this to conduct cross-site scripting (XSS) attacks.
(CVE-2013-1670)
It was discovered that the file input element could expose the full local
path under certain conditions. An attacker could potentially exploit this
to steal sensitive information. (CVE-2013-1671)
A use-after-free was discovered when resizing video co...
The problem can be corrected by updating your system to the following package versions: Ubuntu 13.04: firefox 21.0+build2-0ubuntu0.13.04.2 Ubuntu 12.10: firefox 21.0+build2-0ubuntu0.12.10.2 Ubuntu 12.04 LTS: firefox 21.0+build2-0ubuntu0.12.04.3 After a standard system update you need to restart Firefox to make all the necessary changes.
https://ubuntu.com/security/notices/USN-1822-1
CVE-2013-0801, CVE-2013-1669, CVE-2013-1670, CVE-2013-1671,
CVE-2013-1674, CVE-2013-1675, CVE-2013-1676, CVE-2013-1677,
CVE-2013-1678, CVE-2013-1679, CVE-2013-1680, CVE-2013-1681,
https://bugs.launchpad.net/ubuntu/+source/firefox/+bug/1178277
Get the latest Linux and open source security news straight to your inbox.