USN-3124-1: Firefox vulnerabilities
USN-3124-1: Firefox vulnerabilities Ubuntu Security Notice USN-3124-1 18th November, 2016 firefox vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 16.10 Ubuntu 16.04 LTS Ubuntu 14.04 LTS Ubuntu 12.04 LTS Summary Firefox could be made to crash or run programs as your login if it opened a malicious website. Software description firefox – Mozilla Open Source web browser Details Christian Holler, Andrew McCreight, Dan Minor, Tyson Smith, Jon Coppeard,Jan-Ivar Bruaroey, Jesse Ruderman, Markus Stange, Olli Pettay, EhsanAkhgari, Gary Kwong, Tooru Fujisawa, and Randell Jesup discovered multiplememory safety issues in Firefox. If a user were tricked in to opening aspecially crafted website, an attacker could potentially exploit these tocause a denial of service via application crash, or execute arbitrarycode. (CVE-2016-5289, CVE-2016-5290) A same-origin policy bypass was discovered with local HTML files in somecircumstances. An attacker could potentially [ more… ]