Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 515
Alerts This Week
Warning Icon 1 515

Ubuntu 16.04 LTS USN-3044-1 Critical: Firefox Remote Exploit Information

ubuntu
Calendar Grey August 5, 2016
Scroller Ubuntu
Ubuntu tackles significant Chrome security flaws, reducing the chances of system failures and external threats compromising user information.
Firefox could be made to crash or run programs as your login if it opened a malicious website.

Summary

Firefox could be made to crash or run programs as your login if it

opened a malicious website.

Software Description:

- firefox: Mozilla Open Source web browser

Details:

Gustavo Grieco discovered an out-of-bounds read during XML parsing in

some circumstances. If a user were tricked in to opening a specially

crafted website, an attacker could potentially exploit this to cause a

denial of service via application crash, or obtain sensitive information.

(CVE-2016-0718)

Toni Huttunen discovered that once a favicon is requested from a site,

the remote server can keep the network connection open even after the page

is closed. A remote attacked could potentially exploit this to track

users, resulting in information disclosure. (CVE-2016-2830)

Christian Holler, Tyson Smith, Boris Zbarsky, Byron Campen, Julian Seward,

Carsten Book, Gary Kwong, Jesse Ruderman, Andrew McCreight, and Phil

Ringnalda discovered multiple memory safety issues in Firefox. If a user

were tr...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 16.04 LTS:
  firefox                         48.0+build2-0ubuntu0.16.04.1

Ubuntu 14.04 LTS:
  firefox                         48.0+build2-0ubuntu0.14.04.1

Ubuntu 12.04 LTS:
  firefox                         48.0+build2-0ubuntu0.12.04.1

After a standard system update you need to restart Firefox to make
all the necessary changes.

References

https://ubuntu.com/security/notices/USN-3044-1

CVE-2016-0718, CVE-2016-2830, CVE-2016-2835, CVE-2016-2836,

CVE-2016-2837, CVE-2016-2838, CVE-2016-2839, CVE-2016-5250,

CVE-2016-5251, CVE-2016-5252, CVE-2016-5254, CVE-2016-5255,

CVE-2016-5258, CVE-2016-5259, CVE-2016-5260, CVE-2016-5261,

CVE-2016-5262, CVE-2016-5263, CVE-2016-5264, CVE-2016-5265,

CVE-2016-5266, CVE-2016-5268

Severity
critical
Lowest
Low
Medium
High
Critical

August 05, 2016

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.