USN-2656-2: Firefox vulnerabilities
15 July 2015
Firefox could be made to crash or run programs as your login if it opened a malicious website.
Releases
Packages
- firefox - Mozilla Open Source web browser
Details
USN-2656-1 fixed vulnerabilities in Firefox for Ubuntu 14.04 LTS and
later releases.
This update provides the corresponding update for Ubuntu 12.04 LTS.
Original advisory details:
Karthikeyan Bhargavan discovered that NSS incorrectly handled state
transitions for the TLS state machine. If a remote attacker were able to
perform a machine-in-the-middle attack, this flaw could be exploited to skip
the ServerKeyExchange message and remove the forward-secrecy property.
(CVE-2015-2721)
Looben Yan discovered 2 use-after-free issues when using XMLHttpRequest in
some circumstances. If a user were tricked in to opening a specially
crafted website, an attacker could potentially exploit these to cause a
denial of service via application crash, or execute arbitrary code with
the privileges of the user invoking Firefox. (CVE-2015-2722,
CVE-2015-2733)
Bob Clary, Christian Holler, Bobby Holley, Andrew McCreight, Terrence
Cole, Steve Fink, Mats Palmgren, Wes Kocher, Andreas Pehrson, Tooru
Fujisawa, Andrew Sutherland, and Gary Kwong discovered multiple memory
safety issues in Firefox. If a user were tricked in to opening a specially
crafted website, an attacker could potentially exploit these to cause a
denial of service via application crash, or execute arbitrary code with
the privileges of the user invoking Firefox. (CVE-2015-2724,
CVE-2015-2725, CVE-2015-2726)
Armin Razmdjou discovered that opening hyperlinks with specific mouse
and key combinations could allow a Chrome privileged URL to be opened
without context restrictions being preserved. If a user were tricked in to
opening a specially crafted website, an attacker could potentially exploit
this to bypass security restrictions. (CVE-2015-2727)
Paul Bandha discovered a type confusion bug in the Indexed DB Manager. If
a user were tricked in to opening a specially crafted website, an attacker
could potentially exploit this to cause a denial of service via
application crash or execute arbitrary code with the priviliges of the
user invoking Firefox. (CVE-2015-2728)
Holger Fuhrmannek discovered an out-of-bounds read in Web Audio. If a
user were tricked in to opening a specially crafted website, an attacker
could potentially exploit this to obtain sensitive information.
(CVE-2015-2729)
Watson Ladd discovered that NSS incorrectly handled Elliptical Curve
Cryptography (ECC) multiplication. A remote attacker could possibly use
this issue to spoof ECDSA signatures. (CVE-2015-2730)
A use-after-free was discovered when a Content Policy modifies the DOM to
remove a DOM object. If a user were tricked in to opening a specially
crafted website, an attacker could potentially exploit this to cause a
denial of service via application crash or execute arbitrary code with the
priviliges of the user invoking Firefox. (CVE-2015-2731)
Ronald Crane discovered multiple security vulnerabilities. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service via application
crash, or execute arbitrary code with the privileges of the user invoking
Firefox. (CVE-2015-2734, CVE-2015-2735, CVE-2015-2736, CVE-2015-2737,
CVE-2015-2738, CVE-2015-2739, CVE-2015-2740)
David Keeler discovered that key pinning checks can be skipped when an
overridable certificate error occurs. This allows a user to manually
override an error for a fake certificate, but cannot be exploited on its
own. (CVE-2015-2741)
Jonas Jenwald discovered that some internal workers were incorrectly
executed with a high privilege. If a user were tricked in to opening a
specially crafted website, an attacker could potentially exploit this in
combination with another security vulnerability, to execute arbitrary code
in a privileged scope. (CVE-2015-2743)
Matthew Green discovered a DHE key processing issue in NSS where a MITM
could force a server to downgrade TLS connections to 512-bit export-grade
cryptography. An attacker could potentially exploit this to impersonate
the server. (CVE-2015-4000)
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 12.04
After a standard system update you need to restart Firefox to make
all the necessary changes.
References
Related notices
- USN-2673-1: thunderbird-locale-mk, thunderbird-dev, thunderbird-locale-pt, thunderbird-locale-sr, thunderbird-locale-sv-se, thunderbird-locale-et, thunderbird-locale-gd, thunderbird-locale-zh-tw, thunderbird-locale-ta, thunderbird-locale-id, thunderbird-locale-nn-no, thunderbird-locale-bn-bd, xul-ext-lightning, thunderbird-locale-pa, thunderbird-locale-en-gb, thunderbird-locale-ast, thunderbird, thunderbird-locale-br, thunderbird-locale-af, thunderbird-locale-eu, thunderbird-locale-ar, thunderbird-locale-el, thunderbird-locale-en-us, thunderbird-locale-hu, thunderbird-locale-ro, xul-ext-calendar-timezones, xul-ext-gdata-provider, thunderbird-locale-rm, thunderbird-locale-hy, thunderbird-locale-pa-in, thunderbird-locale-fy-nl, thunderbird-locale-zh-hant, thunderbird-testsuite, thunderbird-locale-en, thunderbird-locale-es-es, thunderbird-locale-ko, thunderbird-locale-es, thunderbird-locale-es-ar, thunderbird-locale-ru, thunderbird-locale-sv, thunderbird-locale-nb-no, thunderbird-locale-zh-hans, thunderbird-locale-fr, thunderbird-locale-sk, thunderbird-gnome-support, thunderbird-locale-bn, thunderbird-locale-he, thunderbird-locale-tr, thunderbird-locale-vi, thunderbird-locale-de, thunderbird-locale-sl, thunderbird-locale-ta-lk, thunderbird-globalmenu, thunderbird-locale-pt-pt, thunderbird-locale-sq, thunderbird-mozsymbols, thunderbird-locale-ja, thunderbird-locale-nn, thunderbird-locale-be, thunderbird-locale-da, thunderbird-locale-fy, thunderbird-locale-nl, thunderbird-locale-si, thunderbird-locale-lt, thunderbird-locale-pl, thunderbird-locale-ca, thunderbird-locale-ka, thunderbird-locale-uk, thunderbird-locale-it, thunderbird-locale-is, thunderbird-locale-nb, thunderbird-locale-fi, thunderbird-locale-pt-br, thunderbird-locale-zh-cn, thunderbird-locale-cs, thunderbird-locale-ga, thunderbird-locale-bg, thunderbird-locale-ga-ie, thunderbird-locale-gl, thunderbird-locale-hr
- USN-2672-1: libnss3-dev, libnss3-tools, libnss3, libnss3-nssdb, libnss3-1d, nss
- USN-2656-1: firefox-locale-lt, firefox-locale-vi, firefox-locale-hy, firefox-locale-kn, firefox-locale-as, firefox-locale-lv, firefox-locale-uk, firefox-locale-de, firefox-locale-az, firefox-locale-eu, firefox-locale-nb, firefox-locale-pt, firefox-locale-sk, firefox-locale-gl, firefox-locale-km, firefox-locale-is, firefox-locale-pa, firefox-locale-ca, firefox-locale-si, firefox-locale-fy, firefox-locale-kk, firefox-locale-ast, firefox-locale-nso, firefox-locale-el, firefox-locale-te, firefox-locale-br, firefox-locale-ko, firefox-locale-nn, firefox-locale-hu, firefox-locale-tr, firefox-locale-nl, firefox-locale-th, firefox-locale-es, firefox-locale-ga, firefox-locale-id, firefox-locale-ml, firefox-locale-mr, firefox-locale-gu, firefox-locale-sl, firefox-locale-en, firefox-locale-or, firefox-locale-sr, firefox-locale-he, firefox-locale-csb, firefox-locale-ru, firefox-locale-xh, firefox-locale-sq, firefox-locale-an, firefox-locale-sv, firefox-dev, firefox, firefox-locale-fi, firefox-locale-ja, firefox-testsuite, firefox-locale-fa, firefox-locale-uz, firefox-locale-gd, firefox-locale-zu, firefox-locale-da, firefox-locale-oc, firefox-locale-bs, firefox-locale-bg, firefox-locale-fr, firefox-locale-ku, firefox-globalmenu, firefox-locale-mk, firefox-locale-be, firefox-locale-hr, firefox-locale-sw, firefox-locale-mai, firefox-locale-ar, firefox-locale-it, firefox-locale-mn, firefox-locale-zh-hant, firefox-locale-hi, firefox-locale-bn, firefox-locale-ms, firefox-locale-lg, firefox-locale-ta, firefox-locale-cy, firefox-locale-ro, firefox-locale-eo, firefox-locale-hsb, firefox-locale-et, firefox-mozsymbols, firefox-locale-zh-hans, firefox-locale-pl, firefox-locale-ka, firefox-locale-af, firefox-locale-cs
- 2696-1: openjdk-7-jdk, openjdk-7-jre, openjdk-7-jre-headless, openjdk-7, openjdk-7-jre-zero, openjdk-7-jre-lib, icedtea-7-jre-jamvm
- USN-2706-1: openjdk-6-jre-headless, openjdk-6, openjdk-6-jdk, openjdk-6-jre-zero, icedtea-6-jre-cacao, openjdk-6-source, openjdk-6-jre, openjdk-6-jre-lib, icedtea-6-jre-jamvm
- USN-2696-1: openjdk-7-jdk, openjdk-7-jre, openjdk-7-jre-headless, openjdk-7-demo, openjdk-7, openjdk-7-jre-zero, openjdk-7-doc, openjdk-7-jre-lib, openjdk-7-source, icedtea-7-jre-jamvm