Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Firefox could be made to crash or run programs as your login if it
opened a malicious website.
Software Description:
- firefox: Mozilla Open Source web browser
Details:
Ben Turner, Bobby Holley, Jesse Ruderman, Christian Holler and Christoph
Diehl discovered multiple memory safety issues in Firefox. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service via application
crash, or execute arbitrary code with the privileges of the user invoking
Firefox. (CVE-2013-5609, CVE-2013-5610)
Myk Melez discovered that the doorhanger notification for web app
installation could persist between page navigations. An attacker could
potentially exploit this to conduct clickjacking attacks. (CVE-2013-5611)
Masato Kinugawa discovered that pages with missing character set encoding
information can inherit character encodings across navigations from
another domain. An attacker could potentially exploit this to conduct
...
The problem can be corrected by updating your system to the following package versions: Ubuntu 13.10: firefox 26.0+build2-0ubuntu0.13.10.2 Ubuntu 13.04: firefox 26.0+build2-0ubuntu0.13.04.2 Ubuntu 12.10: firefox 26.0+build2-0ubuntu0.12.10.2 Ubuntu 12.04 LTS: firefox 26.0+build2-0ubuntu0.12.04.2 After a standard system update you need to restart Firefox to make all the necessary changes.
https://ubuntu.com/security/notices/USN-2052-1
CVE-2013-5609, CVE-2013-5610, CVE-2013-5611, CVE-2013-5612,
CVE-2013-5613, CVE-2013-5614, CVE-2013-5615, CVE-2013-5616,
CVE-2013-5618, CVE-2013-5619, CVE-2013-6629, CVE-2013-6630,
CVE-2013-6671, CVE-2013-6672, CVE-2013-6673,https://bugs.launchpad.net/ubuntu/+source/firefox/+bug/1258513
Get the latest Linux and open source security news straight to your inbox.