USN-930-1: Firefox and Xulrunner vulnerabilities

29 June 2010

Firefox could be made to run programs as your login if it opened a specially crafted file or website.

Reduce your security exposure

Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.

Learn more about Ubuntu Pro

Releases

Packages

Details

If was discovered that Firefox could be made to access freed memory. If a
user were tricked into viewing a malicious site, a remote attacker could
cause a denial of service or possibly execute arbitrary code with the
privileges of the user invoking the program. This issue only affected
Ubuntu 8.04 LTS. (CVE-2010-1121)

Several flaws were discovered in the browser engine of Firefox. If a
user were tricked into viewing a malicious site, a remote attacker could
cause a denial of service or possibly execute arbitrary code with the
privileges of the user invoking the program. (CVE-2010-1200, CVE-2010-1201,
CVE-2010-1202, CVE-2010-1203)

A flaw was discovered in the way plugin instances interacted. An attacker
could potentially exploit this and use one plugin to access freed memory from a
second plugin to execute arbitrary code with the privileges of the user
invoking the program. (CVE-2010-1198)

An integer overflow was discovered in Firefox. If a user were tricked into
viewing a malicious site, an attacker could overflow a buffer and cause a
denial of service or possibly execute arbitrary code with the privileges of
the user invoking the program. (CVE-2010-1196)

Martin Barbella discovered an integer overflow in an XSLT node sorting
routine. An attacker could exploit this to overflow a buffer and cause a
denial of service or possibly execute arbitrary code with the privileges of
the user invoking the program. (CVE-2010-1199)

Michal Zalewski discovered that the focus behavior of Firefox could be
subverted. If a user were tricked into viewing a malicious site, a remote
attacker could use this to capture keystrokes. (CVE-2010-1125)

Ilja van Sprundel discovered that the 'Content-Disposition: attachment'
HTTP header was ignored when 'Content-Type: multipart' was also present.
Under certain circumstances, this could potentially lead to cross-site
scripting attacks. (CVE-2010-1197)

Amit Klein discovered that Firefox did not seed its random number generator
often enough. An attacker could exploit this to identify and track users
across different web sites. (CVE-2008-5913)

Reduce your security exposure

Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.

Learn more about Ubuntu Pro

Update instructions

The problem can be corrected by updating your system to the following package versions:

Ubuntu 8.04
Ubuntu 10.04

Mozilla has changed the support model for Firefox and they no longer
support version 3.0 of the browser. As a result, Ubuntu is providing an
upgrade to Firefox 3.6 for Ubuntu 8.04 LTS users, which is the most current
stable release of Firefox supported by Mozilla. When upgrading, users
should be aware of the following:

  • Firefox 3.6 does not support version 5 of the Sun Java plugin. Please use
    icedtea-java7-plugin or sun-java6-plugin instead.
  • After upgrading to Firefox 3.6.6, users may be prompted to upgrade 3rd
    party Add-Ons. In some cases, an Add-On will not be compatible with
    Firefox 3.6.6 and have no update available. In these cases, Firefox will
    notify the user that it is disabling the Add-On.
  • Upgrades to Ubuntu 8.10 from Ubuntu 8.04 LTS may break the browser.
    Ubuntu 8.10 is no longer officially supported and users are required to
    upgrade to 9.04 to receive active security support and a functional browser.
  • Font configuration cannot be controlled via Gnome settings. This is a
    known issue being tracked in https://launchpad.net/bugs/559149 and will
    be fixed in a later update.
  • helix-player is not currently supported in Firefox 3.6. This is a known
    issue and may be fixed in a future update.
  • RealAudio via the totem plugin is no longer supported in Firefox 3.6 in
    Ubuntu 8.04 LTS. Affected users navigating to Real content will be
    prompted to install optional community supported packages.
  • In Ubuntu 8.04 LTS the xine plugin is non-functional. After upgrading to
    Firefox 3.6, the plugin may cause the browser to crash, while in Firefox
    3.0 it would be silently ignored. Users are advised to uninstall
    xine-plugin and/or gxineplugin.
  • Plugins using external helpers (such as Totem) may not close when using
    the Epiphany browser. This is a known issue being tracked in
    https://launchpad.net/bugs/599796 and will be fixed in a later update.
    This issue only affects Ubuntu 8.04 LTS.

After a standard system upgrade you need to restart Firefox and any
applications that use Xulrunner to effect the necessary changes.

Related notices