{"id":33081,"date":"2019-09-26T00:03:01","date_gmt":"2019-09-25T15:03:01","guid":{"rendered":"https:\/\/jirak.net\/wp\/usn-4140-1-firefox-vulnerability\/"},"modified":"2019-09-26T00:34:38","modified_gmt":"2019-09-25T15:34:38","slug":"usn-4140-1-firefox-vulnerability","status":"publish","type":"post","link":"https:\/\/jirak.net\/wp\/usn-4140-1-firefox-vulnerability\/","title":{"rendered":"USN-4140-1: Firefox vulnerability"},"content":{"rendered":"<p>USN-4140-1: Firefox vulnerability<\/p>\n<h2 id=\"firefox-vulnerability\">firefox vulnerability<\/h2>\n<p>A security issue affects these releases of Ubuntu and its derivatives:<\/p>\n<ul>\n<li>Ubuntu 19.04<\/li>\n<li>Ubuntu 18.04 LTS<\/li>\n<li>Ubuntu 16.04 LTS<\/li>\n<\/ul>\n<h3 id=\"summary\">Summary<\/h3>\n<p>Firefox could be made to hijack the mouse pointer it if opened a malicious<br \/>\nwebsite.<\/p>\n<h3 id=\"software-description\">Software Description<\/h3>\n<ul>\n<li>firefox &#8211; Mozilla Open Source web browser<\/li>\n<\/ul>\n<h3 id=\"details\">Details<\/h3>\n<p>It was discovered that no user notification was given when pointer lock is<br \/>\nenabled. If a user were tricked in to opening a specially crafted website,<br \/>\nan attacker could potentially exploit this to hijack the mouse pointer and<br \/>\nconfuse users.<\/p>\n<h2 id=\"update-instructions\">Update instructions<\/h2>\n<p>The problem can be corrected by updating your system to the following package versions:<\/p>\n<dl>\n<dt>Ubuntu 19.04<\/dt>\n<dd><a href=\"https:\/\/launchpad.net\/ubuntu\/+source\/firefox\">firefox<\/a> &#8211; <a href=\"https:\/\/launchpad.net\/ubuntu\/+source\/firefox\/69.0.1+build1-0ubuntu0.19.04.1\">69.0.1+build1-0ubuntu0.19.04.1<\/a><\/dd>\n<dt>Ubuntu 18.04 LTS<\/dt>\n<dd><a href=\"https:\/\/launchpad.net\/ubuntu\/+source\/firefox\">firefox<\/a> &#8211; <a href=\"https:\/\/launchpad.net\/ubuntu\/+source\/firefox\/69.0.1+build1-0ubuntu0.18.04.1\">69.0.1+build1-0ubuntu0.18.04.1<\/a><\/dd>\n<dt>Ubuntu 16.04 LTS<\/dt>\n<dd><a href=\"https:\/\/launchpad.net\/ubuntu\/+source\/firefox\">firefox<\/a> &#8211; <a href=\"https:\/\/launchpad.net\/ubuntu\/+source\/firefox\/69.0.1+build1-0ubuntu0.16.04.1\">69.0.1+build1-0ubuntu0.16.04.1<\/a><\/dd>\n<\/dl>\n<p>To update your system, please follow these instructions: <a href=\"https:\/\/wiki.ubuntu.com\/Security\/Upgrades\">https:\/\/wiki.ubuntu.com\/Security\/Upgrades<\/a>.<\/p>\n<p>After a standard system update you need to restart Firefox to make<br \/>\nall the necessary changes.<\/p>\n<h2 id=\"references\">References<\/h2>\n<ul>\n<li><a href=\"https:\/\/people.canonical.com\/~ubuntu-security\/cve\/CVE-2019-11754\">CVE-2019-11754<\/a><\/li>\n<\/ul>\n<p>Source: <a href=\"https:\/\/usn.ubuntu.com\/4140-1\/\" target=\"_blank\" rel=\"noopener noreferrer\">USN-4140-1: Firefox vulnerability<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<div class=\"mh-excerpt\"><p>USN-4140-1: Firefox vulnerability firefox vulnerability A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 19.04 Ubuntu 18.04 LTS Ubuntu 16.04 LTS Summary Firefox could be made to hijack the mouse pointer it if opened a malicious website. Software Description firefox &#8211; Mozilla Open Source web browser Details It was discovered that no user notification was given when pointer lock is enabled. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to hijack the mouse pointer and confuse users. Update instructions The problem can be corrected by updating your system to the following package versions: Ubuntu 19.04 firefox &#8211; 69.0.1+build1-0ubuntu0.19.04.1 Ubuntu 18.04 LTS firefox &#8211; 69.0.1+build1-0ubuntu0.18.04.1 Ubuntu 16.04 LTS firefox &#8211; 69.0.1+build1-0ubuntu0.16.04.1 To update your system, please follow these instructions: https:\/\/wiki.ubuntu.com\/Security\/Upgrades. After a standard system update you need to <a class=\"mh-excerpt-more\" href=\"https:\/\/jirak.net\/wp\/usn-4140-1-firefox-vulnerability\/\" title=\"USN-4140-1: Firefox vulnerability\">[ more&#8230; ]<\/a><\/p>\n<\/div>","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[586],"tags":[587],"class_list":["post-33081","post","type-post","status-publish","format-standard","hentry","category-ubuntu-usn","tag-ubuntu-usn"],"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/jirak.net\/wp\/wp-json\/wp\/v2\/posts\/33081","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/jirak.net\/wp\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/jirak.net\/wp\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/jirak.net\/wp\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/jirak.net\/wp\/wp-json\/wp\/v2\/comments?post=33081"}],"version-history":[{"count":1,"href":"https:\/\/jirak.net\/wp\/wp-json\/wp\/v2\/posts\/33081\/revisions"}],"predecessor-version":[{"id":33082,"href":"https:\/\/jirak.net\/wp\/wp-json\/wp\/v2\/posts\/33081\/revisions\/33082"}],"wp:attachment":[{"href":"https:\/\/jirak.net\/wp\/wp-json\/wp\/v2\/media?parent=33081"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/jirak.net\/wp\/wp-json\/wp\/v2\/categories?post=33081"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/jirak.net\/wp\/wp-json\/wp\/v2\/tags?post=33081"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}