Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
USN-2702-1 introduced a regression in Firefox.
Software Description:
- firefox: Mozilla Open Source web browser
Details:
USN-2702-1 fixed vulnerabilities in Firefox. After upgrading, some users
in the US reported that their default search engine switched to Yahoo.
This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Gary Kwong, Christian Holler, Byron Campen, Tyson Smith, Bobby Holley,
Chris Coulson, and Eric Rahm discovered multiple memory safety issues in
Firefox. If a user were tricked in to opening a specially crafted website,
an attacker could potentially exploit these to cause a denial of service
via application crash, or execute arbitrary code with the privileges of
the user invoking Firefox. (CVE-2015-4473, CVE-2015-4474)
Aki Helin discovered an out-of-bounds read when playing malformed MP3
content in some circumstances. If a user were tricked in to opening a
specially crafted website, an att...
The problem can be corrected by updating your system to the following package versions: Ubuntu 15.04: firefox 40.0+build4-0ubuntu0.15.04.4 Ubuntu 14.04 LTS: firefox 40.0+build4-0ubuntu0.14.04.4 Ubuntu 12.04 LTS: firefox 40.0+build4-0ubuntu0.12.04.4 After a standard system update you need to restart Firefox to make all the necessary changes.
https://ubuntu.com/security/notices/USN-2702-3
https://ubuntu.com/security/notices/USN-2702-1
https://bugs.launchpad.net/ubuntu/+source/firefox/+bug/1485741
Get the latest Linux and open source security news straight to your inbox.