Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
USN-2917-1 introduced several regressions in Firefox.
Software Description:
- firefox: Mozilla Open Source web browser
Details:
USN-2917-1 fixed vulnerabilities in Firefox. This update caused several
web compatibility regressions.
This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
Francis Gabriel discovered a buffer overflow during ASN.1 decoding in NSS.
If a user were tricked in to opening a specially crafted website, an
attacker could potentially exploit this to cause a denial of service via
application crash, or execute arbitrary code with the privileges of the
user invoking Firefox. (CVE-2016-1950)
Bob Clary, Christoph Diehl, Christian Holler, Andrew McCreight, Daniel
Holbert, Jesse Ruderman, Randell Jesup, Carsten Book, Gian-Carlo Pascutto,
Tyson Smith, Andrea Marchesini, and Jukka Jylänki discovered multiple
memory safety issues in Firefox. If a user were tricked in to opening a
speciall...
The problem can be corrected by updating your system to the following package versions: Ubuntu 15.10: firefox 45.0.2+build1-0ubuntu0.15.10.1 Ubuntu 14.04 LTS: firefox 45.0.2+build1-0ubuntu0.14.04.1 Ubuntu 12.04 LTS: firefox 45.0.2+build1-0ubuntu0.12.04.1 After a standard system update you need to restart Firefox to make all the necessary changes.
https://ubuntu.com/security/notices/USN-2917-3
https://ubuntu.com/security/notices/USN-2917-1
https://bugs.launchpad.net/ubuntu/+source/firefox/+bug/1572169
Get the latest Linux and open source security news straight to your inbox.