QID 198704
Date Published: 2022-03-21
QID 198704: Ubuntu Security Notification for Firefox Vulnerabilities (USN-5321-2)
Ubuntu has released a security update for firefox to fix the vulnerabilities.
Usn-5321-1 fixed vulnerabilities in firefox.
The update didn't includearm64 because of a regression.
This update provides the correspondingupdate for arm64.
Ru as optional search providersin the drop-down search menu.
Original advisory details:multiple security issues were discovered in firefox.
If a user were tricked into opening a specially crafted website, an attacker could potentially exploit these to cause a denial of service, spoof the browser ui, bypass security restrictions, obtain sensitive information, or execute arbitrary code.
(cve-2022-0843, cve-2022-26381, cve-2022-26382,cve-2022-26383, cve-2022-26384, cve-2022-26385)a toctou bug was discovered when verifying addon signatures during install.
A local attacker could potentially exploit this to trick a user into installing an addon with an invalid signature.
- USN-5321-2 -
ubuntu.com/security/notices/USN-5321-2
CVEs related to QID 198704
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| USN-5321-2 | Ubuntu Linux |
|