You are here
Home > Preporuke > Sigurnosni nedostaci programskog paketa firefox

Sigurnosni nedostaci programskog paketa firefox

==========================================================================
Ubuntu Security Notice USN-4165-1
October 23, 2019

firefox vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

– Ubuntu 19.10
– Ubuntu 19.04
– Ubuntu 18.04 LTS
– Ubuntu 16.04 LTS

Summary:

Firefox could be made to crash or run programs as your login if it
opened a malicious website.

Software Description:
– firefox: Mozilla Open Source web browser

Details:

Multiple security issues were discovered in Firefox. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service, bypass security
restrictions, bypass same-origin restrictions, conduct cross-site
scripting (XSS) attacks, bypass content security policy (CSP)
protections, or execute arbitrary code.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 19.10:
firefox 70.0+build2-0ubuntu0.19.10.1

Ubuntu 19.04:
firefox 70.0+build2-0ubuntu0.19.04.1

Ubuntu 18.04 LTS:
firefox 70.0+build2-0ubuntu0.18.04.1

Ubuntu 16.04 LTS:
firefox 70.0+build2-0ubuntu0.16.04.1

After a standard system update you need to restart Firefox to make
all the necessary changes.

References:
https://usn.ubuntu.com/4165-1
CVE-2018-6156, CVE-2019-11757, CVE-2019-11759, CVE-2019-11760,
CVE-2019-11761, CVE-2019-11762, CVE-2019-11763, CVE-2019-11764,
CVE-2019-11765, CVE-2019-15903, CVE-2019-17000, CVE-2019-17001,
CVE-2019-17002

Package Information:
https://launchpad.net/ubuntu/+source/firefox/70.0+build2-0ubuntu0.19.10.1
https://launchpad.net/ubuntu/+source/firefox/70.0+build2-0ubuntu0.19.04.1
https://launchpad.net/ubuntu/+source/firefox/70.0+build2-0ubuntu0.18.04.1
https://launchpad.net/ubuntu/+source/firefox/70.0+build2-0ubuntu0.16.04.1

—–BEGIN PGP SIGNATURE—–

iQEzBAEBCgAdFiEERN//5MGgCOgyKeIFYR+97NWUbg8FAl2w15AACgkQYR+97NWU
bg+GKwgAnfh75dryyBcSQdz8JUl57BE0jPyiHuQXnaTSc+o3QtF2NtFH+XrTLL+g
+kEZa1BZIrl6rmHe57WknJv+9lhWhIaBoij5wNPWm3EA+UZlz6pZvuCvC+4we/+a
aPS6tub97/nZ3R6cFCChadOPngimMn3M7XPs+b4M/uCQuTZ050T73I5meiFsp/6X
PQ/32sLPwKQtQiPBhf0unjcDiD2/pM7ZklSS6OmvviKk2Nv8ILzHrcQzVoVzS9O/
jbZIUMGkUOltlYAHk3yHII/O0o69pyersY7fZs/AzM/E8jh26ATtmeGCJVbKonCj
8GMGZTrdX2Cquo9x2CalhNna62KLuA==
=iKlA
—–END PGP SIGNATURE—–

Top
More in Preporuke
Sigurnosni nedostaci programskog paketa Red Hat Satellite 6

Otkriveni su sigurnosni nedostaci u programskom paketu Red Hat Satellite 6 za operacijski sustav RHEL. Otkriveni nedostaci potencijalnim napadačima omogućuju...

Close