Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 426
Alerts This Week
Warning Icon 1 426

Ubuntu: 4625-1 Moderate: Firefox Crash And Code Execution Threat

ubuntu
Calendar Grey November 10, 2020
Scroller Ubuntu
Ubuntu 20.04 along with various other systems are vulnerable to a critical Firefox flaw that can lead to executing arbitrary code through harmful websites.
Firefox could be made to crash or run programs as your login if it opened a malicious website.

Summary

Firefox could be made to crash or run programs as your login if it

opened a malicious website.

Software Description:

- firefox: Mozilla Open Source web browser

Details:

A use-after-free was discovered in Firefox. If a user were tricked in

to opening a specially crafted website, an attacker could exploit this

to execute arbitrary code.

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 20.10:
  firefox                         82.0.3+build1-0ubuntu0.20.10.1

Ubuntu 20.04 LTS:
  firefox                         82.0.3+build1-0ubuntu0.20.04.1

Ubuntu 18.04 LTS:
  firefox                         82.0.3+build1-0ubuntu0.18.04.1

Ubuntu 16.04 LTS:
  firefox                         82.0.3+build1-0ubuntu0.16.04.1

After a standard system update you need to restart Firefox to make
all the necessary changes.

References

https://ubuntu.com/security/notices/USN-4625-1

CVE-2020-26950

Severity
important
Lowest
Low
Medium
High
Critical

November 10, 2020

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.