Firefox could be made to crash or run programs as your login if it
opened a malicious website.
Software Description:
- firefox: Mozilla Open Source web browser
Details:
USN-4599-1 fixed vulnerabilities in Firefox. This update provides the
corresponding updates for Ubuntu 16.04 LTS.
Original advisory details:
Multiple security issues were discovered in Firefox. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service, spoof the prompt
for opening an external application, obtain sensitive information, or
execute
arbitrary code.
The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 LTS: firefox 82.0+build2-0ubuntu0.16.04.5 After a standard system update you need to restart Firefox to make all the necessary changes.
https://ubuntu.com/security/notices/USN-4599-2
https://ubuntu.com/security/notices/USN-4599-1
CVE-2020-15254, CVE-2020-15680, CVE-2020-15681, CVE-2020-15682,
CVE-2020-15683, CVE-2020-15684, CVE-2020-15969
Get the latest Linux and open source security news straight to your inbox.