what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

Ubuntu Security Notice USN-4978-1

Ubuntu Security Notice USN-4978-1
Posted Jun 3, 2021
Authored by Ubuntu | Site security.ubuntu.com

Ubuntu Security Notice 4978-1 - Multiple security issues were discovered in Firefox. If a user were tricked into opening a specially crafted website, an attacker could potentially exploit these to cause a denial of service, re-enable camera devices without an additional permission prompt, spoof the browser UI, or execute arbitrary code. It was discovered that filenames printed from private browsing mode were incorrectly retained in preferences. A local attacker could potentially exploit this to obtain sensitive information. Various other issues were also addressed.

tags | advisory, denial of service, arbitrary, local, spoof
systems | linux, ubuntu
advisories | CVE-2021-29959, CVE-2021-29960, CVE-2021-29966, CVE-2021-29967
SHA-256 | ce7cb751faf214f237878175293abf7868671eed89542795ea494fa088d21830

Ubuntu Security Notice USN-4978-1

Change Mirror Download
==========================================================================
Ubuntu Security Notice USN-4978-1
June 02, 2021

firefox vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 21.04
- Ubuntu 20.10
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS

Summary:

Firefox could be made to crash or run programs as your login if it
opened a malicious website.

Software Description:
- firefox: Mozilla Open Source web browser

Details:

Multiple security issues were discovered in Firefox. If a user were
tricked into opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service, re-enable
camera devices without an additional permission prompt, spoof the browser
UI, or execute arbitrary code. (CVE-2021-29959, CVE-2021-29961,
CVE-2021-29966, CVE-2021-29967)

It was discovered that filenames printed from private browsing mode were
incorrectly retained in preferences. A local attacker could potentially
exploit this to obtain sensitive information. (CVE-2021-29960)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 21.04:
firefox 89.0+build2-0ubuntu0.21.04.1

Ubuntu 20.10:
firefox 89.0+build2-0ubuntu0.20.10.1

Ubuntu 20.04 LTS:
firefox 89.0+build2-0ubuntu0.20.04.2

Ubuntu 18.04 LTS:
firefox 89.0+build2-0ubuntu0.18.04.2

After a standard system update you need to restart Firefox to make
all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-4978-1
CVE-2021-29959, CVE-2021-29960, CVE-2021-29961, CVE-2021-29966,
CVE-2021-29967

Package Information:
https://launchpad.net/ubuntu/+source/firefox/89.0+build2-0ubuntu0.21.04.1
https://launchpad.net/ubuntu/+source/firefox/89.0+build2-0ubuntu0.20.10.1
https://launchpad.net/ubuntu/+source/firefox/89.0+build2-0ubuntu0.20.04.2
https://launchpad.net/ubuntu/+source/firefox/89.0+build2-0ubuntu0.18.04.2
Login or Register to add favorites

File Archive:

February 2023

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Feb 1st
    11 Files
  • 2
    Feb 2nd
    0 Files
  • 3
    Feb 3rd
    0 Files
  • 4
    Feb 4th
    0 Files
  • 5
    Feb 5th
    0 Files
  • 6
    Feb 6th
    0 Files
  • 7
    Feb 7th
    0 Files
  • 8
    Feb 8th
    0 Files
  • 9
    Feb 9th
    0 Files
  • 10
    Feb 10th
    0 Files
  • 11
    Feb 11th
    0 Files
  • 12
    Feb 12th
    0 Files
  • 13
    Feb 13th
    0 Files
  • 14
    Feb 14th
    0 Files
  • 15
    Feb 15th
    0 Files
  • 16
    Feb 16th
    0 Files
  • 17
    Feb 17th
    0 Files
  • 18
    Feb 18th
    0 Files
  • 19
    Feb 19th
    0 Files
  • 20
    Feb 20th
    0 Files
  • 21
    Feb 21st
    0 Files
  • 22
    Feb 22nd
    0 Files
  • 23
    Feb 23rd
    0 Files
  • 24
    Feb 24th
    0 Files
  • 25
    Feb 25th
    0 Files
  • 26
    Feb 26th
    0 Files
  • 27
    Feb 27th
    0 Files
  • 28
    Feb 28th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Hosting By
Rokasec
close