USN-3140-1: Firefox vulnerabilities
USN-3140-1: Firefox vulnerabilities Ubuntu Security Notice USN-3140-1 30th November, 2016 firefox vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 16.10 Ubuntu 16.04 LTS Ubuntu 14.04 LTS Ubuntu 12.04 LTS Summary Firefox could be made to crash or run programs as your login if it opened a malicious website. Software description firefox – Mozilla Open Source web browser Details It was discovered that data: URLs can inherit the wrong origin after aHTTP redirect in some circumstances. An attacker could potentiallyexploit this to bypass same-origin restrictions. (CVE-2016-9078) A use-after-free was discovered in SVG animations. If a user were trickedin to opening a specially crafted website, an attacker could exploit thisto cause a denial of service via application crash, or execute arbitrarycode. (CVE-2016-9079) Update instructions The problem can be corrected by updating your system to the following package [ more… ]