=========================================================================Ubuntu Security Notice USN-2993-1 June 09, 2016 firefox vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 16.04 LTS - Ubuntu 15.10 - Ubuntu 14.04 LTS - Ubuntu 12.04 LTS Summary: Firefox could be made to crash or run programs as your login if it opened a malicious website. Software Description: - firefox: Mozilla Open Source web browser Details: Christian Holler, Gary Kwong, Jesse Ruderman, Tyson Smith, Timothy Nikkel, Sylvestre Ledru, Julian Seward, Olli Pettay, Karl Tomlinson, Christoph Diehl, Julian Hector, Jan de Mooij, Mats Palmgren, and Tooru Fujisawa discovered multiple memory safety issues in Firefox. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit these to cause a denial of service via application crash, or execute arbitrary code. (CVE-2016-2815, CVE-2016-2818) A buffer overflow was discovered when parsing HTML5 fragments in some circumstances. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to cause a denial of service via application crash, or execute arbitrary code. (CVE-2016-2819) A use-after-free was discovered in contenteditable mode in some circumstances. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to cause a denial of service via application crash, or execute arbitrary code. (CVE-2016-2821) Jordi Chancel discovered a way to use a persistent menu within a
The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 LTS: firefox 47.0+build3-0ubuntu0.16.04.1 Ubuntu 15.10: firefox 47.0+build3-0ubuntu0.15.10.1 Ubuntu 14.04 LTS: firefox 47.0+build3-0ubuntu0.14.04.1 Ubuntu 12.04 LTS: firefox 47.0+build3-0ubuntu0.12.04.1 After a standard system update you need to restart Firefox to make all the necessary changes.
https://ubuntu.com/security/notices/USN-2993-1
CVE-2016-2815, CVE-2016-2818, CVE-2016-2819, CVE-2016-2821,
CVE-2016-2822, CVE-2016-2825, CVE-2016-2828, CVE-2016-2829,
CVE-2016-2831, CVE-2016-2832, CVE-2016-2833, CVE-2016-2834
https://launchpad.net/ubuntu/+source/firefox/47.0+build3-0ubuntu0.16.04.1 https://launchpad.net/ubuntu/+source/firefox/47.0+build3-0ubuntu0.15.10.1 https://launchpad.net/ubuntu/+source/firefox/47.0+build3-0ubuntu0.14.04.1 https://launchpad.net/ubuntu/+source/firefox/47.0+build3-0ubuntu0.12.04.1
Get the latest Linux and open source security news straight to your inbox.