Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

Ubuntu 20.04 LTS USN-5954-1 Critical Firefox Denial of Service

ubuntu
Calendar Grey March 16, 2023
Scroller Ubuntu
The Ubuntu Security Notice USN-5954-1 addresses severe vulnerabilities in Firefox, risking user data and system integrity. Update promptly to protect your system.
Several security issues were fixed in Firefox.

Summary

Several security issues were fixed in Firefox.

Software Description:

- firefox: Mozilla Open Source web browser

Details:

Multiple security issues were discovered in Firefox. If a user were

tricked into opening a specially crafted website, an attacker could

potentially exploit these to cause a denial of service, obtain sensitive

information across domains, or execute arbitrary code. (CVE-2023-25750,

CVE-2023-25752, CVE-2023-28162, CVE-2023-28176, CVE-2023-28177)

Lukas Bernhard discovered that Firefox did not properly manage memory

when invalidating JIT code while following an iterator. An attacker could

potentially exploits this issue to cause a denial of service.

(CVE-2023-25751)

Rob Wu discovered that Firefox did not properly manage the URLs when

following a redirect to a publicly accessible web extension file. An

attacker could potentially exploits this to obtain sensitive information.

(CVE-2023-28160)

Luan Herrera discovered that Firefox did not properly manage cross-origin

...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 20.04 LTS:
  firefox                         111.0+build2-0ubuntu0.20.04.1

Ubuntu 18.04 LTS:
  firefox                         111.0+build2-0ubuntu0.18.04.1

After a standard system update you need to restart Firefox to make all the
necessary changes.

References

https://ubuntu.com/security/notices/USN-5954-1

CVE-2023-25750, CVE-2023-25751, CVE-2023-25752, CVE-2023-28160,

CVE-2023-28161, CVE-2023-28162, CVE-2023-28164, CVE-2023-28176,

CVE-2023-28177

Severity
critical
Lowest
Low
Medium
High
Critical

March 15, 2023

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.