Site icon 지락문화예술공작단

USN-2866-1: Firefox vulnerability

Ubuntu Security Notice USN-2866-1

8th January, 2016

firefox vulnerability

A security issue affects these releases of Ubuntu and its
derivatives:

Summary

Firefox could be made to expose sensitive information over the network.

Software description

Details

Karthikeyan Bhargavan and Gaetan Leurent discovered that NSS incorrectly
allowed MD5 to be used for TLS 1.2 connections. If a remote attacker were
able to perform a man-in-the-middle attack, this flaw could be exploited to
view sensitive information.

Update instructions

The problem can be corrected by updating your system to the following
package version:

Ubuntu 15.10:
firefox

43.0.4+build3-0ubuntu0.15.10.1
Ubuntu 15.04:
firefox

43.0.4+build3-0ubuntu0.15.04.1
Ubuntu 14.04 LTS:
firefox

43.0.4+build3-0ubuntu0.14.04.1
Ubuntu 12.04 LTS:
firefox

43.0.4+build3-0ubuntu0.12.04.1

To update your system, please follow these instructions:
https://wiki.ubuntu.com/Security/Upgrades.

After a standard system update you need to restart Firefox to make
all the necessary changes.

References

CVE-2015-7575

Source: ubuntu-usn

Exit mobile version