Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 501
Alerts This Week
Warning Icon 1 501

Ubuntu 13.10: 2052-1 Critical: Firefox Memory Safety Issues

ubuntu
Calendar Grey December 11, 2013
Scroller Ubuntu
The recent Ubuntu Security Notice USN-2053-1 points out critical vulnerabilities in the Chromium browser that may compromise user safety and privacy.
Firefox could be made to crash or run programs as your login if itopened a malicious website.

Summary

Firefox could be made to crash or run programs as your login if it

opened a malicious website.

Software Description:

- firefox: Mozilla Open Source web browser

Details:

Ben Turner, Bobby Holley, Jesse Ruderman, Christian Holler and Christoph

Diehl discovered multiple memory safety issues in Firefox. If a user were

tricked in to opening a specially crafted website, an attacker could

potentially exploit these to cause a denial of service via application

crash, or execute arbitrary code with the privileges of the user invoking

Firefox. (CVE-2013-5609, CVE-2013-5610)

Myk Melez discovered that the doorhanger notification for web app

installation could persist between page navigations. An attacker could

potentially exploit this to conduct clickjacking attacks. (CVE-2013-5611)

Masato Kinugawa discovered that pages with missing character set encoding

information can inherit character encodings across navigations from

another domain. An attacker could potentially exploit this to conduct

...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 13.10:
   firefox                         26.0+build2-0ubuntu0.13.10.2

Ubuntu 13.04:
   firefox                         26.0+build2-0ubuntu0.13.04.2

Ubuntu 12.10:
   firefox                         26.0+build2-0ubuntu0.12.10.2

Ubuntu 12.04 LTS:
   firefox                         26.0+build2-0ubuntu0.12.04.2

After a standard system update you need to restart Firefox to make
all the necessary changes.

References

https://ubuntu.com/security/notices/USN-2052-1

CVE-2013-5609, CVE-2013-5610, CVE-2013-5611, CVE-2013-5612,

CVE-2013-5613, CVE-2013-5614, CVE-2013-5615, CVE-2013-5616,

CVE-2013-5618, CVE-2013-5619, CVE-2013-6629, CVE-2013-6630,

CVE-2013-6671, CVE-2013-6672, CVE-2013-6673,https://bugs.launchpad.net/ubuntu/+source/firefox/+bug/1258513

Severity
critical
Lowest
Low
Medium
High
Critical

December 11, 2013

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.