Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

Ubuntu 13.04, 12.10, 12.04 LTS: USN-1951-1 Moderate: Firefox Issues

ubuntu
Calendar Grey September 17, 2013
Scroller Ubuntu
Security issues in Firefox on Ubuntu might cause system crashes or unauthorized code execution by active users. Ensure updates are applied to reduce exposure.
Firefox could be made to crash or run programs as your login if it opened a malicious website.

Summary

Firefox could be made to crash or run programs as your login if it

opened a malicious website.

Software Description:

- firefox: Mozilla Open Source web browser

Details:

Multiple memory safety issues were discovered in Firefox. If a user were

tricked in to opening a specially crafted page, an attacker could possibly

exploit these to cause a denial of service via application crash, or

potentially execute arbitrary code with the privileges of the user

invoking Firefox. (CVE-2013-1718, CVE-2013-1719)

Atte Kettunen discovered a flaw in the HTML5 Tree Builder when interacting

with template elements. In some circumstances, an attacker could

potentially exploit this to execute arbitrary code with the privileges of

the user invoking Firefox. (CVE-2013-1720)

Alex Chapman discovered an integer overflow vulnerability in the ANGLE

library. An attacker could potentially exploit this to execute arbitrary

code with the privileges of the user invoking Firefox. (CVE-2013-1...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 13.04:
  firefox                         24.0+build1-0ubuntu0.13.04.1

Ubuntu 12.10:
  firefox                         24.0+build1-0ubuntu0.12.10.1

Ubuntu 12.04 LTS:
  firefox                         24.0+build1-0ubuntu0.12.04.1

After a standard system update you need to restart Firefox to make
all the necessary changes.

References

https://ubuntu.com/security/notices/USN-1951-1

CVE-2013-1718, CVE-2013-1719, CVE-2013-1720, CVE-2013-1721,

CVE-2013-1722, CVE-2013-1724, CVE-2013-1725, CVE-2013-1728,

CVE-2013-1730, CVE-2013-1732, CVE-2013-1735, CVE-2013-1736,

CVE-2013-1737, CVE-2013-1738, https://bugs.launchpad.net/ubuntu/+source/firefox/+bug/1223826

Severity
important
Lowest
Low
Medium
High
Critical

September 17, 2013

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.