Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Firefox could be made to crash or run programs as your login if it
opened a malicious website.
Software Description:
- firefox: Mozilla Open Source web browser
Details:
Andrei Vaida, Jesse Ruderman, Bob Clary, Christian Holler, Jesse Ruderman,
Eric Rahm, Robert Kaiser, Harald Kirschner, and Michael Henretty
discovered multiple memory safety issues in Firefox. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service via application
crash, or execute arbitrary code with the privileges of the user invoking
Firefox. (CVE-2015-7201, CVE-2015-7202)
Ronald Crane discovered three buffer overflows through code inspection.
If a user were tricked in to opening a specially crafted website, an
attacker could potentially exploit these to cause a denial of service via
application crash, or execute arbitrary code with the privileges of the
user invoking Firefox. (CVE-2015-7203, CVE-2015-7220,...
The problem can be corrected by updating your system to the following package versions: Ubuntu 15.10: firefox 43.0+build1-0ubuntu0.15.10.1 Ubuntu 15.04: firefox 43.0+build1-0ubuntu0.15.04.1 Ubuntu 14.04 LTS: firefox 43.0+build1-0ubuntu0.14.04.1 Ubuntu 12.04 LTS: firefox 43.0+build1-0ubuntu0.12.04.1 After a standard system update you need to restart Firefox to make all the necessary changes.
https://ubuntu.com/security/notices/USN-2833-1
CVE-2015-7201, CVE-2015-7202, CVE-2015-7203, CVE-2015-7204,
CVE-2015-7205, CVE-2015-7207, CVE-2015-7208, CVE-2015-7210,
CVE-2015-7211, CVE-2015-7212, CVE-2015-7213, CVE-2015-7214,
CVE-2015-7215, CVE-2015-7216, CVE-2015-7217, CVE-2015-7218,
CVE-2015-7219, CVE-2015-7220, CVE-2015-7221, CVE-2015-7222,
CVE-2015-7223
Get the latest Linux and open source security news straight to your inbox.