==========================================================================
Ubuntu Security Notice USN-3552-1
January 31, 2018
firefox vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
– Ubuntu 17.10
– Ubuntu 16.04 LTS
– Ubuntu 14.04 LTS
Summary:
Firefox could be made to run programs as your login if it opened a
malicious website.
Software Description:
– firefox: Mozilla Open Source web browser
Details:
Johann Hofmann discovered that HTML fragments created for
chrome-privileged documents were not properly sanitized. An attacker
could exploit this to execute arbitrary code. (CVE-2018-5124)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 17.10:
firefox 58.0.1+build1-0ubuntu0.17.10.1
Ubuntu 16.04 LTS:
firefox 58.0.1+build1-0ubuntu0.16.04.1
Ubuntu 14.04 LTS:
firefox 58.0.1+build1-0ubuntu0.14.04.1
After a standard system update you need to restart Firefox to make
all the necessary changes.
References:
https://www.ubuntu.com/usn/usn-3552-1
CVE-2018-5124
Package Information:
https://launchpad.net/ubuntu/+source/firefox/58.0.1+build1-0ubuntu0.17.10.1
https://launchpad.net/ubuntu/+source/firefox/58.0.1+build1-0ubuntu0.16.04.1
https://launchpad.net/ubuntu/+source/firefox/58.0.1+build1-0ubuntu0.14.04.1
—–BEGIN PGP SIGNATURE—–
iQEcBAEBCAAGBQJacfcdAAoJEGEfvezVlG4PYWMIAKmHfdJmXMZ6okraRWmEyiMH
FCdoQaf0HBQQEeARkj5bga2eE0FGliTT+dWRi3wZi2PdtfKAyxQQVayhn+sDuwnm
nCazvvg3i9k2AR1G9gV5bdnE8El7OFA8caV7hlM7ug0vbFqLSw4J+vZQ7rDSNGk+
rMEsFuNXLAViChvo5viO9vS1Ax6fTvnP5VhbiHut1JUK9NcIiugldrDmGQLWYrto
AQHpM8IdWZzvhaIM1+0UGf/YrNYFsJts3UcEHj7DHwcCABMW6ghy91dICDJ5IaDj
BvSkO8KS319hqNeuPeMReLjQ6h/Tzbm9xic2Pl1qhYuJIxZ6incL0385/1FEKCs=
=O3Tx
—–END PGP SIGNATURE—–
—