QID 198733

Date Published: 2022-04-08

QID 198733: Ubuntu Security Notification for Firefox Vulnerabilities (USN-5370-1)

Selecting text caused firefox to crash in somecircumstances.

Multiple security issues were discovered in firefox.
If a user weretricked into opening a specially crafted website, an attacker couldpotentially exploit these to cause a denial of service, execute scriptunexpectedly, obtain sensitive information, conduct spoofing attacks,or execute arbitrary code.
(cve-2022-1097, cve-2022-24713, cve-2022-28281,cve-2022-28282, cve-2022-28284, cve-2022-28285, cve-2022-28286,cve-2022-28288, cve-2022-28289)a security issue was discovered with the sourcemapurl feature of devtools.
An attacker could potentially exploit this to include local files thatshould have been inaccessible.
An attacker could potentially exploit this to cause adenial of service.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Refer to Ubuntu security advisory USN-5370-1 for updates and patch information.
    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    USN-5370-1 Ubuntu Linux URL Logo ubuntu.com/security/notices/USN-5370-1