USN-3477-1: Firefox vulnerabilities
USN-3477-1: Firefox vulnerabilities Ubuntu Security Notice USN-3477-1 16th November, 2017 firefox vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 17.10 Ubuntu 17.04 Ubuntu 16.04 LTS Ubuntu 14.04 LTS Summary Firefox could be made to crash or run programs as your login if it opened a malicious website. Software description firefox – Mozilla Open Source web browser Details Multiple security issues were discovered in Firefox. If a user weretricked in to opening a specially crafted website, an attacker couldpotentially exploit these to cause a denial of service, read uninitializedmemory, obtain sensitive information, bypass same-origin restrictions,bypass CSP protections, bypass mixed content blocking, spoof theaddressbar, or execute arbitrary code. (CVE-2017-7826, CVE-2017-7827,CVE-2017-7828, CVE-2017-7830, CVE-2017-7831, CVE-2017-7832, CVE-2017-7833,CVE-2017-7834, CVE-2017-7835, CVE-2017-7837, CVE-2017-7838, CVE-2017-7842) It was discovered that javascript: URLs pasted in to the addressbarwould be executed instead of being blocked in some [ more… ]