==========================================================================
Ubuntu Security Notice USN-3896-1
February 26, 2019
firefox vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
– Ubuntu 18.10
– Ubuntu 18.04 LTS
– Ubuntu 16.04 LTS
– Ubuntu 14.04 LTS
Summary:
Firefox could be made to crash or run programs as your login if it
opened a malicious website.
Software Description:
– firefox: Mozilla Open Source web browser
Details:
Multiple security issues were discovered in Firefox. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service, bypass same
origin protections, or execute arbitrary code.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 18.10:
firefox 65.0.1+build2-0ubuntu0.18.10.1
Ubuntu 18.04 LTS:
firefox 65.0.1+build2-0ubuntu0.18.04.1
Ubuntu 16.04 LTS:
firefox 65.0.1+build2-0ubuntu0.16.04.1
Ubuntu 14.04 LTS:
firefox 65.0.1+build2-0ubuntu0.14.04.1
After a standard system update you need to restart Firefox to make
all the necessary changes.
References:
https://usn.ubuntu.com/usn/usn-3896-1
CVE-2018-18356, CVE-2018-18511, CVE-2019-5785
Package Information:
https://launchpad.net/ubuntu/+source/firefox/65.0.1+build2-0ubuntu0.18.10.1
https://launchpad.net/ubuntu/+source/firefox/65.0.1+build2-0ubuntu0.18.04.1
https://launchpad.net/ubuntu/+source/firefox/65.0.1+build2-0ubuntu0.16.04.1
https://launchpad.net/ubuntu/+source/firefox/65.0.1+build2-0ubuntu0.14.04.1
—–BEGIN PGP SIGNATURE—–
iQEzBAEBCgAdFiEERN//5MGgCOgyKeIFYR+97NWUbg8FAlx1jtAACgkQYR+97NWU
bg+FGggAqCDep9VgqCFlPqm/+3cIJD5yfkufNSs1BF9GeObMjlbohthxgApe2Xkm
ZDOR/EBhaqqAVSeprC3lkhEJfVmjSmuUngyfp9A/lW3fGZKY9Ffak7HvlL4J23s1
oS4kcx+G9CFBhK6nOArq9HG4Um8ZY6nOkxfe5E4CKE2tVeHbsuqEvB/awAxTUIs3
JhmtX8vhuiJjHinJdFORcFRZsSio1BW1Us/HUNBFIuebmT3NMLhj9Ti8ebKYarDB
2BUTjXttgtEOmyC6Izq8hrkmNp0/l4igyq/SrXxXvVA1E6k3didaqxW+tujpzS5r
+llLnNHf2NSCZGt35IVtvEX51M4dnA==
=8UJG
—–END PGP SIGNATURE—–
—