Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Firefox could be made to crash or run programs as your login if it
opened a malicious website.
Software Description:
- firefox: Mozilla Open Source web browser
Details:
Christian Holler, David Major, Jesse Ruderman, Tyson Smith, Boris Zbarsky,
Randell Jesup, Olli Pettay, Karl Tomlinson, Jeff Walden, Gary Kwong,
Andrew McCreight, Georg Fritzsche, and Carsten Book discovered multiple
memory safety issues in Firefox. If a user were tricked in to opening a
specially crafted website, an attacker could potentially exploit these to
cause a denial of service via application crash, or execute arbitrary
code with the privileges of the user invoking Firefox. (CVE-2015-4513,
CVE-2015-4514)
Tim Brown discovered that Firefox discloses the hostname during NTLM
authentication in some circumstances. If a user were tricked in to
opening a specially crafted website with NTLM v1 enabled, an attacker
could exploit this to obtain sensitive information. (CVE-2015-4515)
Mario H...
The problem can be corrected by updating your system to the following package versions: Ubuntu 15.10: firefox 42.0+build2-0ubuntu0.15.10.1 Ubuntu 15.04: firefox 42.0+build2-0ubuntu0.15.04.1 Ubuntu 14.04 LTS: firefox 42.0+build2-0ubuntu0.14.04.1 Ubuntu 12.04 LTS: firefox 42.0+build2-0ubuntu0.12.04.1 After a standard system update you need to restart Firefox to make all the necessary changes.
https://ubuntu.com/security/notices/USN-2785-1
CVE-2015-4513, CVE-2015-4514, CVE-2015-4515, CVE-2015-4518,
CVE-2015-7181, CVE-2015-7182, CVE-2015-7183, CVE-2015-7187,
CVE-2015-7188, CVE-2015-7189, CVE-2015-7193, CVE-2015-7194,
CVE-2015-7195, CVE-2015-7196, CVE-2015-7197, CVE-2015-7198,
CVE-2015-7199, CVE-2015-7200
Get the latest Linux and open source security news straight to your inbox.