Login
Newsletter
Werbung

Sicherheit: Zwei Probleme in Mozilla Firefox
Aktuelle Meldungen Distributionen
Name: Zwei Probleme in Mozilla Firefox
ID: USN-1608-1
Distribution: Ubuntu
Plattformen: Ubuntu 10.04 LTS, Ubuntu 11.04, Ubuntu 11.10, Ubuntu 12.04 LTS
Datum: Fr, 12. Oktober 2012, 12:11
Referenzen: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4191
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4192
Applikationen: Mozilla Firefox

Originalnachricht

This is an OpenPGP/MIME signed message (RFC 2440 and 3156)
--===============3754857041365810084==
Content-Type: multipart/signed; micalg=pgp-sha1;
protocol="application/pgp-signature";
boundary="------------enig394954FAA8EFB62670126C8D"

This is an OpenPGP/MIME signed message (RFC 2440 and 3156)
--------------enig394954FAA8EFB62670126C8D
Content-Type: text/plain; charset=UTF-
Content-Transfer-Encoding: quoted-printable

==========================================================================
Ubuntu Security Notice USN-1608-1
October 11, 2012

firefox vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 12.04 LTS
- Ubuntu 11.10
- Ubuntu 11.04
- Ubuntu 10.04 LTS

Summary:

Several security issues were fixed in Firefox.

Software Description:
- firefox: Mozilla Open Source web browser

Details:

It was discovered that the browser engine used in Firefox contained a
memory corruption flaw. If a user were tricked into opening a specially
crafted web page, a remote attacker could cause Firefox to crash or
potentially execute arbitrary code as the user invoking the program.
(CVE-2012-4191)

It was discovered that Firefox allowed improper access to the Location
object. An attacker could exploit this to obtain sensitive information.
(CVE-2012-4192)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 12.04 LTS:
firefox 16.0.1+build1-0ubuntu0.12.04.1

Ubuntu 11.10:
firefox 16.0.1+build1-0ubuntu0.11.10.1

Ubuntu 11.04:
firefox 16.0.1+build1-0ubuntu0.11.04.1

Ubuntu 10.04 LTS:
firefox 16.0.1+build1-0ubuntu0.10.04.1

After a standard system update you need to restart Firefox to make
all the necessary changes.

References:
http://www.ubuntu.com/usn/usn-1608-1
CVE-2012-4191, CVE-2012-4192, https://launchpad.net/bugs/1065285

Package Information:
https://launchpad.net/ubuntu/+source/firefox/16.0.1+build1-0ubuntu0.12.04.1
https://launchpad.net/ubuntu/+source/firefox/16.0.1+build1-0ubuntu0.11.10.1
https://launchpad.net/ubuntu/+source/firefox/16.0.1+build1-0ubuntu0.11.04.1
https://launchpad.net/ubuntu/+source/firefox/16.0.1+build1-0ubuntu0.10.04.1






--------------enig394954FAA8EFB62670126C8D
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
Content-Disposition: attachment; filename="signature.asc"

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)

iEYEARECAAYFAlB3K5IACgkQTniv4aqX/VliZACfekLOl6jw7wbonKUkCjXErxp4
YVgAn1EhB283V6kSxq3J36q27vC7ypI6
=o4KL
-----END PGP SIGNATURE-----

--------------enig394954FAA8EFB62670126C8D--


--===============3754857041365810084==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

--
ubuntu-security-announce mailing list
ubuntu-security-announce@lists.ubuntu.com
Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce

--===============3754857041365810084==--
Pro-Linux
Gewinnspiel
Neue Nachrichten
Werbung