Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
USN-2743-1 introduced a regression in Firefox.
Software Description:
- firefox: Mozilla Open Source web browser
Details:
USN-2743-1 fixed vulnerabilities in Firefox. After upgrading, some users
reported problems with bookmark creation and crashes in some
circumstances. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Andrew Osmond, Olli Pettay, Andrew Sutherland, Christian Holler, David
Major, Andrew McCreight, Cameron McCormack, Bob Clary and Randell Jesup
discovered multiple memory safety issues in Firefox. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service via application
crash, or execute arbitrary code with the privileges of the user invoking
Firefox. (CVE-2015-4500, CVE-2015-4501)
André Bargull discovered that when a web page creates a scripted proxy
for the window with a handler defined a certain way, ...
The problem can be corrected by updating your system to the following package versions: Ubuntu 15.04: firefox 41.0.1+build2-0ubuntu0.15.04.2 Ubuntu 14.04 LTS: firefox 41.0.1+build2-0ubuntu0.14.04.1 Ubuntu 12.04 LTS: firefox 41.0.1+build2-0ubuntu0.12.04.1 After a standard system update you need to restart Firefox to make all the necessary changes.
https://ubuntu.com/security/notices/USN-2743-4
https://ubuntu.com/security/notices/USN-2743-1
https://bugs.launchpad.net/ubuntu/+source/firefox/+bug/1501277
Get the latest Linux and open source security news straight to your inbox.