Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Ubuntu 21.10 USN-5370-1 Moderate: Firefox Crash From Malicious Site

Ubuntu Large Esm H500
Firefox could be made to crash or run programs as your login if it opened a malicious website.
=========================================================================Ubuntu Security Notice USN-5370-1
April 07, 2022

firefox vulnerabilities
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 21.10
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS

Summary:

Firefox could be made to crash or run programs as your login if it
opened a malicious website.

Software Description:
- firefox: Mozilla Open Source web browser

Details:

Multiple security issues were discovered in Firefox. If a user were
tricked into opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service, execute script
unexpectedly, obtain sensitive information, conduct spoofing attacks,
or execute arbitrary code. (CVE-2022-1097, CVE-2022-24713, CVE-2022-28281,
CVE-2022-28282, CVE-2022-28284, CVE-2022-28285, CVE-2022-28286,
CVE-2022-28288, CVE-2022-28289)

A security issue was discovered with the sourceMapURL feature of devtools.
An attacker could potentially exploit this to include local files that
should have been inaccessible. (CVE-2022-28283)

It was discovered that selecting text caused Firefox to crash in some
circumstances. An attacker could potentially exploit this to cause a
denial of service. (CVE-2022-28287)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 21.10:
  firefox                         99.0+build2-0ubuntu0.21.10.2

Ubuntu 20.04 LTS:
  firefox                         99.0+build2-0ubuntu0.20.04.2

Ubuntu 18.04 LTS:
  firefox                         99.0+build2-0ubuntu0.18.04.2

After a standard system update you need to restart Firefox to make
all the necessary changes.

References:
  
  CVE-2022-1097, CVE-2022-24713, CVE-2022-28281, CVE-2022-28282,
  CVE-2022-28283, CVE-2022-28284, CVE-2022-28285, CVE-2022-28286,
  CVE-2022-28287, CVE-2022-28288, CVE-2022-28289

Package Information:
  https://launchpad.net/ubuntu/+source/firefox/99.0+build2-0ubuntu0.21.10.2
  https://launchpad.net/ubuntu/+source/firefox/99.0+build2-0ubuntu0.20.04.2
  https://launchpad.net/ubuntu/+source/firefox/99.0+build2-0ubuntu0.18.04.2

Ubuntu 21.10 USN-5370-1 Moderate: Firefox Crash From Malicious Site

ubuntu
Calendar Grey April 7, 2022
Dist Ubuntu Esm H88
Ubuntu's Mozilla Firefox could face risks of crashes and potential execution of harmful code through compromised webpages.
Firefox could be made to crash or run programs as your login if it opened a malicious website.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 21.10: firefox 99.0+build2-0ubuntu0.21.10.2 Ubuntu 20.04 LTS: firefox 99.0+build2-0ubuntu0.20.04.2 Ubuntu 18.04 LTS: firefox 99.0+build2-0ubuntu0.18.04.2 After a standard system update you need to restart Firefox to make all the necessary changes.

References

CVE-2022-1097, CVE-2022-24713, CVE-2022-28281, CVE-2022-28282,

CVE-2022-28283, CVE-2022-28284, CVE-2022-28285, CVE-2022-28286,

CVE-2022-28287, CVE-2022-28288, CVE-2022-28289

April 07, 2022

Package Information

https://launchpad.net/ubuntu/+source/firefox/99.0+build2-0ubuntu0.21.10.2 https://launchpad.net/ubuntu/+source/firefox/99.0+build2-0ubuntu0.20.04.2 https://launchpad.net/ubuntu/+source/firefox/99.0+build2-0ubuntu0.18.04.2

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here