Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 514
Alerts This Week
Warning Icon 1 514

Ubuntu 15.04 USN-2768-1 Critical: Firefox Information Exposure Risk

ubuntu
Calendar Grey October 16, 2015
Scroller Ubuntu
Ubuntu Security Advisory USN-2768-1 addresses a vulnerability in Firefox that risks revealing confidential information. Ensure you revise your system to safeguard against this threat.
Firefox could be made to expose sensitive information across origins

Summary

Firefox could be made to expose sensitive information across origins

Software Description:

- firefox: Mozilla Open Source web browser

Details:

Abdulrahman Alqabandi and Ben Kelly discovered that the fetch() API did

not correctly implement the Cross Origin Resource Sharing (CORS)

specification. If a user were tricked in to opening a specially crafted

website, an attacker could potentially exploit this to obtain sensitive

information from other origins. (CVE-2015-7184)

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 15.04:
  firefox                         41.0.2+build2-0ubuntu0.15.04.1

Ubuntu 14.04 LTS:
  firefox                         41.0.2+build2-0ubuntu0.14.04.1

Ubuntu 12.04 LTS:
  firefox                         41.0.2+build2-0ubuntu0.12.04.1

After a standard system update you need to restart Firefox to make
all the necessary changes.

References

CVE-2015-7184

Severity
critical
Lowest
Low
Medium
High
Critical

October 16, 2015

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.