QID 198696
Date Published: 2022-03-14
QID 198696: Ubuntu Security Notification for Firefox Vulnerabilities (USN-5321-1)
Ubuntu has released a security update for firefox to fix the vulnerabilities.
Multiple security issues were discovered in firefox.
If a user weretricked into opening a specially crafted website, an attacker couldpotentially exploit these to cause a denial of service, spoof the browserui, bypass security restrictions, obtain sensitive information, or executearbitrary code.
(cve-2022-0843, cve-2022-26381, cve-2022-26382,cve-2022-26383, cve-2022-26384, cve-2022-26385)a toctou bug was discovered when verifying addon signatures duringinstall.
A local attacker could potentially exploit this to trick auser into installing an addon with an invalid signature.
Solution
Refer to Ubuntu security advisory USN-5321-1 for updates and patch information.
Vendor References
- USN-5321-1 -
ubuntu.com/security/notices/USN-5321-1
CVEs related to QID 198696
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| USN-5321-1 | Ubuntu Linux |
|