Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 501
Alerts This Week
Warning Icon 1 501

Ubuntu 13.10 USN-2009-1 Critical: Firefox Memory Flaws Affecting Users

ubuntu
Calendar Grey October 29, 2013
Scroller Ubuntu
Browsers such as Firefox can present security risks for Ubuntu users. Timely updates are essential to shield against potential web threats and app issues
Firefox could be made to crash or run programs as your login if it opened a malicious website.

Summary

Firefox could be made to crash or run programs as your login if it

opened a malicious website.

Software Description:

- firefox: Mozilla Open Source web browser

Details:

Multiple memory safety issues were discovered in Firefox. If a user were

tricked in to opening a specially crafted page, an attacker could possibly

exploit these to cause a denial of service via application crash, or

potentially execute arbitrary code with the privileges of the user

invoking Firefox. (CVE-2013-1739, CVE-2013-5590, CVE-2013-5591,

CVE-2013-5592)

Jordi Chancel discovered that HTML select elements could display arbitrary

content. An attacker could potentially exploit this to conduct

URL spoofing or clickjacking attacks (CVE-2013-5593)

Abhishek Arya discovered a crash when processing XSLT data in some

circumstances. An attacker could potentially exploit this to execute

arbitrary code with the privileges of the user invoking Firefox.

(CVE-2013-5604)

Dan Gohman discovered a f...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 13.10:
  firefox                         25.0+build3-0ubuntu0.13.10.1

Ubuntu 13.04:
  firefox                         25.0+build3-0ubuntu0.13.04.1

Ubuntu 12.10:
  firefox                         25.0+build3-0ubuntu0.12.10.1

Ubuntu 12.04 LTS:
  firefox                         25.0+build3-0ubuntu0.12.04.1

After a standard system update you need to restart Firefox to make
all the necessary changes.

References

CVE-2013-1739, CVE-2013-5590, CVE-2013-5591, CVE-2013-5592,

CVE-2013-5593, CVE-2013-5595, CVE-2013-5596, CVE-2013-5597,

CVE-2013-5598, CVE-2013-5599, CVE-2013-5600, CVE-2013-5601,

CVE-2013-5602, CVE-2013-5603, CVE-2013-5604, https://bugs.launchpad.net/ubuntu/+source/firefox/+bug/1245414

Severity
critical
Lowest
Low
Medium
High
Critical

October 29, 2013

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.