USN-3516-1: Firefox vulnerabilities
5 January 2018
Firefox could be made to expose sensitive information.
Releases
Packages
- firefox - Mozilla Open Source web browser
Details
It was discovered that speculative execution performed by modern CPUs
could leak information through a timing side-channel attack, and that
this could be exploited in web browser JavaScript engines. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit this to obtain sensitive information from other
domains, bypassing same-origin restrictions. (CVE-2017-5715,
CVE-2017-5753, CVE-2017-5754).
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 17.10
Ubuntu 17.04
Ubuntu 16.04
Ubuntu 14.04
After a standard system update you need to restart Firefox to make
all the necessary changes.
References
Related notices
- USN-3530-1
- USN-3594-1
- USN-3580-1
- USN-3620-2
- USN-3541-2
- USN-3531-3
- USN-3560-1
- USN-3531-1
- USN-3540-1
- USN-3540-2
- USN-3561-1
- USN-3549-1
- USN-3777-3
- USN-3581-1
- USN-3690-1
- USN-3582-2
- USN-3597-2
- USN-3541-1
- USN-3597-1
- USN-3582-1
- USN-3542-1
- USN-3542-2
- USN-3581-2
- USN-3521-1
- USN-3523-2
- USN-3522-1
- USN-3522-2
- USN-3524-2
- USN-3524-1
- USN-3523-1
- USN-3525-1
- USN-3583-1