QID 198689

Date Published: 2022-03-07

QID 198689: Ubuntu Security Notification for Firefox Vulnerabilities (USN-5314-1)

Ubuntu has released a security update for firefox to fix the vulnerabilities.

A use-after-free was discovered when removing an xslt parameter in somecircumstances.
If a user were tricked into opening a specially craftedwebsite, an attacker could exploit this to cause a denial of service, orexecute arbitrary code.
(cve-2022-26485)a use-after-free was discovered in the webgpu ipc framework.
If a userwere tricked into opening a specially crafted website, an attacker couldexploit this to cause a denial of service, or execute arbitrary code.

  • CVSS V3 rated as High - 6.2 severity.
  • CVSS V2 rated as Medium - 5.4 severity.
  • Solution
    Refer to Ubuntu security advisory USN-5314-1 for updates and patch information.
    Vendor References

    CVEs related to QID 198689

    Software Advisories
    Advisory ID Software Component Link
    USN-5314-1 Ubuntu Linux URL Logo ubuntu.com/security/notices/USN-5314-1