Cookie Consent by Free Privacy Policy Generator website USN-2917-1: Firefox vulnerabilities Seite: 1 u

Portal Nachrichten

https://tsecurity.de/Suche/Exploit/ Suche funktioniert jetzt wieder inkl. RSS Feeds pro Thema z.B. https://tsecurity.de/RSS/1/Ransomeware/ (1 Alle Kategorien)

➠ USN-2917-1: Firefox vulnerabilities

Ubuntu Security Notice USN-2917-1

9th March, 2016

firefox vulnerabilities

A security issue affects these releases of Ubuntu and its derivatives:

  • Ubuntu 15.10
  • Ubuntu 14.04 LTS
  • Ubuntu 12.04 LTS

Summary

Firefox could be made to crash or run programs as your login if it opened a malicious website.

Software description

  • firefox - Mozilla Open Source web browser

Details

Francis Gabriel discovered a buffer overflow during ASN.1 decoding in NSS.
If a user were tricked in to opening a specially crafted website, an
attacker could potentially exploit this to cause a denial of service via
application crash, or execute arbitrary code with the privileges of the
user invoking Firefox. (CVE-2016-1950)

Bob Clary, Christoph Diehl, Christian Holler, Andrew McCreight, Daniel
Holbert, Jesse Ruderman, Randell Jesup, Carsten Book, Gian-Carlo Pascutto,
Tyson Smith, Andrea Marchesini, and Jukka Jylänki discovered multiple
memory safety issues in Firefox. If a user were tricked in to opening a
specially crafted website, an attacker could potentially exploit these to
cause a denial of service via application crash, or execute arbitrary code
with the privileges of the user invoking Firefox. (CVE-2016-1952,
CVE-2016-1953)

Nicolas Golubovic discovered that CSP violation reports can be used to
overwrite local files. If a user were tricked in to opening a specially
crafted website with addon signing disabled and unpacked addons installed,
an attacker could potentially exploit this to gain additional privileges.
(CVE-2016-1954)

Muneaki Nishimura discovered that CSP violation reports contained full
paths for cross-origin iframe navigations. An attacker could potentially
exploit this to steal confidential data. (CVE-2016-1955)

Ucha Gobejishvili discovered that performing certain WebGL operations
resulted in memory resource exhaustion with some Intel GPUs, requiring
a reboot. If a user were tricked in to opening a specially crafted
website, an attacker could potentially exploit this to cause a denial
of service. (CVE-2016-1956)

Jose Martinez and Romina Santillan discovered a memory leak in
libstagefright during MPEG4 video file processing in some circumstances.
If a user were tricked in to opening a specially crafted website, an
attacker could potentially exploit this to cause a denial of service via
memory exhaustion. (CVE-2016-1957)

Abdulrahman Alqabandi discovered that the addressbar could be blank or
filled with page defined content in some circumstances. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit this to conduct URL spoofing attacks. (CVE-2016-1958)

Looben Yang discovered an out-of-bounds read in Service Worker Manager. If
a user were tricked in to opening a specially crafted website, an attacker
could potentially exploit this to cause a denial of service via
application crash, or execute arbitrary code with the privileges of the
user invoking Firefox. (CVE-2016-1959)

A use-after-free was discovered in the HTML5 string parser. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit this to cause a denial of service via application
crash, or execute arbitrary code with the privileges of the user invoking
Firefox. (CVE-2016-1960)

A use-after-free was discovered in the SetBody function of HTMLDocument.
If a user were tricked in to opening a specially crafted website, an
attacker could potentially exploit this to cause a denial of service via
application crash, or execute arbitrary code with the privileges of the
user invoking Firefox. (CVE-2016-1961)

Dominique Hazaël-Massieux discovered a use-after-free when using multiple
WebRTC data channels. If a user were tricked in to opening a specially
crafted website, an attacker could potentially exploit this to cause a
denial of service via application crash, or execute arbitrary code with
the privileges of the user invoking Firefox. (CVE-2016-1962)

It was discovered that Firefox crashes when local files are modified
whilst being read by the FileReader API. If a user were tricked in to
opening a specially crafted website, an attacker could potentially exploit
this to execute arbitrary code with the privileges of the user invoking
Firefox. (CVE-2016-1963)

Nicolas Grégoire discovered a use-after-free during XML transformations.
If a user were tricked in to opening a specially crafted website, an
attacker could potentially exploit this to cause a denial of service via
application crash, or execute arbitrary code with the privileges of the
user invoking Firefox. (CVE-2016-1964)

Tsubasa Iinuma discovered a mechanism to cause the addressbar to display
an incorrect URL, using history navigations and the Location protocol
property. If a user were tricked in to opening a specially crafted
website, an attacker could potentially exploit this to conduct URL
spoofing attacks. (CVE-2016-1965)

A memory corruption issues was discovered in the NPAPI subsystem. If
a user were tricked in to opening a specially crafted website with a
malicious plugin installed, an attacker could potentially exploit this
to cause a denial of service via application crash, or execute arbitrary
code with the privileges of the user invoking Firefox. (CVE-2016-1966)

Jordi Chancel discovered a same-origin-policy bypass when using
performance.getEntries and history navigation with session restore. If
a user were tricked in to opening a specially crafted website, an attacker
could potentially exploit this to steal confidential data. (CVE-2016-1967)

Luke Li discovered a buffer overflow during Brotli decompression in some
circumstances. If a user were tricked in to opening a specially crafted
website, an attacker could potentially exploit this to cause a denial of
service via application crash, or execute arbitrary code with the
privileges of the user invoking Firefox. (CVE-2016-1968)

Ronald Crane discovered a use-after-free in GetStaticInstance in WebRTC.
If a user were tricked in to opening a specially crafted website, an
attacker could potentially exploit this to cause a denial of service via
application crash, or execute arbitrary code with the privileges of the
user invoking Firefox. (CVE-2016-1973)

Ronald Crane discovered an out-of-bounds read following a failed
allocation in the HTML parser in some circumstances. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit this to cause a denial of service via application
crash, or execute arbitrary code with the privileges of the user invoking
Firefox. (CVE-2016-1974)

Holger Fuhrmannek, Tyson Smith and Holger Fuhrmannek reported multiple
memory safety issues in the Graphite 2 library. If a user were tricked in
to opening a specially crafted website, an attacker could potentially
exploit these to cause a denial of service via application crash, or
execute arbitrary code with the privileges of the user invoking Firefox.
(CVE-2016-1977, CVE-2016-2790, CVE-2016-2791, CVE-2016-2792,
CVE-2016-2793, CVE-2016-2794, CVE-2016-2795, CVE-2016-2796, CVE-2016-2797,
CVE-2016-2798, CVE-2016-2799, CVE-2016-2800, CVE-2016-2801, CVE-2016-2802)

Update instructions

The problem can be corrected by updating your system to the following package version:

Ubuntu 15.10:
firefox 45.0+build2-0ubuntu0.15.10.1
Ubuntu 14.04 LTS:
firefox 45.0+build2-0ubuntu0.14.04.1
Ubuntu 12.04 LTS:
firefox 45.0+build2-0ubuntu0.12.04.1

To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades.

After a standard system update you need to restart Firefox to make
all the necessary changes.

References

CVE-2016-1950, CVE-2016-1952, CVE-2016-1953, CVE-2016-1954, CVE-2016-1955, CVE-2016-1956, CVE-2016-1957, CVE-2016-1958, CVE-2016-1959, CVE-2016-1960, CVE-2016-1961, CVE-2016-1962, CVE-2016-1963, CVE-2016-1964, CVE-2016-1965, CVE-2016-1966, CVE-2016-1967, CVE-2016-1968, CVE-2016-1973, CVE-2016-1974, CVE-2016-1977, CVE-2016-2790, CVE-2016-2791, CVE-2016-2792, CVE-2016-2793, CVE-2016-2794, CVE-2016-2795, CVE-2016-2796, CVE-2016-2797, CVE-2016-2798, CVE-2016-2799, CVE-2016-2800, CVE-2016-2801, CVE-2016-2802

...


➦ Unix Server ☆ ubuntu.com

➠ Komplette Nachricht lesen


Zur Startseite

Kommentiere zu USN-2917-1: Firefox vulnerabilities











➤ Ähnliche Beiträge für 'USN-2917-1: Firefox vulnerabilities'

[Testing Update] 2022-07-27 - Kernels, Cinnamon, AMDVLK, Firefox 103

vom 1154.34 Punkte
Hello community, Another testing branch update with some usual updates for you. Cinnamon 5.4 brings a new version of the Mutter window manager Some of our Kernels got updated Some more Cinnamon updates AMDVLK is now at 2022.Q3.1 Firefox 103 improved performance on high-refresh rate

[Testing Update] 2020-01-09 - Snap, Firefox-Dev, Packagekit, Gnome

vom 1116.12 Punkte
@philm wrote: Hello community, here is another Testing Update for 2020! Tell us how 2019 was for you ... 1125×289Manjaro ARM Team will be at #FOSDEM2020 Some feature-updates: Updated some snap related packages Added the latest Firefox devel

[Testing Update] 2020-01-22 - Linux55, Brave, KDE

vom 1100.83 Punkte
@philm wrote: Hello community, here is another Testing Update ... 1224×685If you missed the last EU BDDL here you go Some feature-updates: linux55 got updated to the last RC brave got updated some KDE fixes The usual upstream fixes If you like following latest Plasma development you may also

[Testing Update] 2022-05-21 - Mesa 22.0.4, Firefox 100.0.2, Qemu

vom 772.11 Punkte
Hello community, Another testing branch update with some usual updates for you. In need an Office-ready MiniPC? Check out the UM350 shipping with KDE Plasma and OnlyOffice pre-installed! Mesa got updated to 22.0.4 Latest Firefox 100.0.2 and beta release Thunderbird 91.9.1 Qemu got s

[Testing Update] 2022-09-26 - Firefox, 0 AD a26, Gradience, Linux Firmware, Wine Staging

vom 772.11 Punkte
Hello community, Another testing branch update with some usual package updates for you. Don’t miss out on 20% discount this weekend on all of our Merch! manjaro.myspreadshop.net Firefox is now at 105.0.1 0 AD got its 26th Alpha released We added gradience to change the look of Adwaita, wit

[Testing Update] 2019-12-04 - Firefox 71, Brave, Plasma 5.17.4, Systemd

vom 764.47 Punkte
@philm wrote: Hello community, I am happy to announce another Testing Update. 840×480Firefox 71 comes with new Kiosk mode and built-in MP3 decoding Some feature-updates: Firefox 71 got added to our repos Firefox-Dev starts in 72

[Testing Update] 2020-06-03 - Software-Center, Arc Themes, Linux 5.7, Firefox 77, Systemd 245.6

vom 764.47 Punkte
Hello community, Another testing branch update with some interesting updates for you! 1920×1080 Get 15% off on our Merch by tomorrow! #stayhome, #staysafe, #stayhealthy* We added our web software center as a package Arc Themes got updated We pushed

[Stable Update] 2020-06-06 - Linux 5.7.0, Firefox 77 and 78, Arc-Themes, Software Center, Haskell, Python

vom 760.64 Punkte
Hello community, Another stable branch update with some interesting updates for you! 1920×1080Get 15% off on our Merch by tomorrow! #stayhome, #staysafe, #stayhealthy We added our web software center as a package Arc Themes got updated We pushed out the final 5

[Stable-Staging Update] 2020-06-05 - Software-Center, Arc Themes, Linux 5.7, Firefox 77, Systemd 245.6

vom 760.64 Punkte
Hello community, Another stable-staging branch update with some interesting updates for you! 1920×1080Get 15% off on our Merch by tomorrow! #stayhome, #staysafe, #stayhealthy We added our web software center as a package Arc Themes got updated We pushed o

[Testing Update] 2020-07-31 - Kernels, Plasma 5.19.4, Firefox 79, Deepin, UKUI, Systemd, Python

vom 760.64 Punkte
Hello community, Another testing branch update with some interesting updates for you! 1280×720 Get the latest #PinePhone images! Phosh, Plasma-Mobile #stayhome, #staysafe, #stayhealthy Most of our Kernels got updated Plasma is now at 5.19.4 Fire

[Testing Update] 2020-10-22 - Firefox, Plasma 5.20.1, Virtualbox 6.1.16, Python, Haskell

vom 760.64 Punkte
Hello community, Another testing branch update with some interesting updates for you! 1920×1080 198 KB Need a T-Shirt or a Mug? Go to our Store and save 20% today! #stayhome, #staysafe, #stayhealthy Firefox is now at 82.0 release First point-release of Plasma 5.20 got released.

[Stable Update] 2019-10-14 - Pamac 9.0, LLVM9, Firefox, KDE Apps 19.08.2

vom 730.06 Punkte
@philm wrote: Hello community, I am happy to announce another Stable Update. Mostly we have updates for our second release candidate of Manjaro 18.1.1. EEblKiqWsAAsjcw?format=jpg&name=large1220×882Pamac 9.0 with Snap