QID 198601

Date Published: 2021-12-10

QID 198601: Ubuntu Security Notification for Firefox Vulnerabilities (USN-5186-1)

Ubuntu has released a security update for firefox to fix the vulnerabilities.

Multiple security issues were discovered in firefox.
If a user weretricked into opening a specially crafted website, an attacker couldpotentially exploit these to cause a denial of service, obtain sensitiveinformation, conduct spoofing attacks, bypass csp restrictions, orexecute arbitrary code.
(cve-2021-43536, cve-2021-43537, cve-2021-43538,cve-2021-43539, cve-2021-43541, cve-2021-43542, cve-2021-43543,cve-2021-43545, cve-2021-43546)a security issue was discovered with the handling of webextensionpermissions.
If a user were tricked into installing a specially craftedextension, an attacker could potentially exploit this to create andinstall a service worker that wouldn't be uninstalled with the extension.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as High - 6.8 severity.
  • Solution
    Refer to Ubuntu security advisory USN-5186-1 for updates and patch information.
    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    USN-5186-1 Ubuntu Linux URL Logo ubuntu.com/security/notices/USN-5186-1