USN-2743-1

Source
https://ubuntu.com/security/notices/USN-2743-1
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-2743-1.json
JSON Data
https://api.osv.dev/v1/vulns/USN-2743-1
Related
Published
2015-09-22T22:08:43.898211Z
Modified
2015-09-22T22:08:43.898211Z
Summary
firefox vulnerabilities
Details

Andrew Osmond, Olli Pettay, Andrew Sutherland, Christian Holler, David Major, Andrew McCreight, Cameron McCormack, Bob Clary and Randell Jesup discovered multiple memory safety issues in Firefox. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit these to cause a denial of service via application crash, or execute arbitrary code with the privileges of the user invoking Firefox. (CVE-2015-4500, CVE-2015-4501)

André Bargull discovered that when a web page creates a scripted proxy for the window with a handler defined a certain way, a reference to the inner window will be passed, rather than that of the outer window. (CVE-2015-4502)

Felix Gröbert discovered an out-of-bounds read in the QCMS color management library in some circumstances. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to cause a denial of service via application crash, or obtain sensitive information. (CVE-2015-4504)

Khalil Zhani discovered a buffer overflow when parsing VP9 content in some circumstances. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to cause a denial of service via application crash, or execute arbitrary code with the privileges of the user invoking Firefox. (CVE-2015-4506)

Spandan Veggalam discovered a crash while using the debugger API in some circumstances. If a user were tricked in to opening a specially crafted website whilst using the debugger, an attacker could potentially exploit this to execute arbitrary code with the privileges of the user invoking Firefox. (CVE-2015-4507)

Juho Nurminen discovered that the URL bar could display the wrong URL in reader mode in some circumstances. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to conduct URL spoofing attacks. (CVE-2015-4508)

A use-after-free was discovered when manipulating HTML media content in some circumstances. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to cause a denial of service via application crash, or execute arbitrary code with the privileges of the user invoking Firefox. (CVE-2015-4509)

Looben Yang discovered a use-after-free when using a shared worker with IndexedDB in some circumstances. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to cause a denial of service via application crash, or execute arbitrary code with the privileges of the user invoking Firefox. (CVE-2015-4510)

Francisco Alonso discovered an out-of-bounds read during 2D canvas rendering in some circumstances. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to obtain sensitive information. (CVE-2015-4512)

Jeff Walden discovered that changes could be made to immutable properties in some circumstances. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to execute arbitrary script in a privileged scope. (CVE-2015-4516)

Ronald Crane reported multiple vulnerabilities. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit these to cause a denial of service via application crash, or execute arbitrary code with the privileges of the user invoking Firefox. (CVE-2015-4517, CVE-2015-4521, CVE-2015-4522, CVE-2015-7174, CVE-2015-7175, CVE-2015-7176, CVE-2015-7177, CVE-2015-7180)

Mario Gomes discovered that dragging and dropping an image after a redirect exposes the redirected URL to scripts. An attacker could potentially exploit this to obtain sensitive information. (CVE-2015-4519)

Ehsan Akhgari discovered 2 issues with CORS preflight requests. An attacker could potentially exploit these to bypass CORS restrictions. (CVE-2015-4520)

References

Affected packages

Ubuntu:14.04:LTS / firefox

Package

Name
firefox
Purl
pkg:deb/ubuntu/firefox?arch=src?distro=trusty

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
41.0+build3-0ubuntu0.14.04.1

Affected versions

24.*

24.0+build1-0ubuntu1

25.*

25.0+build3-0ubuntu0.13.10.1

28.*

28.0~b2+build1-0ubuntu2
28.0+build1-0ubuntu1
28.0+build2-0ubuntu1
28.0+build2-0ubuntu2

29.*

29.0+build1-0ubuntu0.14.04.2

30.*

30.0+build1-0ubuntu0.14.04.3

31.*

31.0+build1-0ubuntu0.14.04.1

32.*

32.0+build1-0ubuntu0.14.04.1
32.0.3+build1-0ubuntu0.14.04.1

33.*

33.0+build2-0ubuntu0.14.04.1

34.*

34.0+build2-0ubuntu0.14.04.1

35.*

35.0+build3-0ubuntu0.14.04.2
35.0.1+build1-0ubuntu0.14.04.1

36.*

36.0+build2-0ubuntu0.14.04.4
36.0.1+build2-0ubuntu0.14.04.1
36.0.4+build1-0ubuntu0.14.04.1

37.*

37.0+build2-0ubuntu0.14.04.1
37.0.1+build1-0ubuntu0.14.04.1
37.0.2+build1-0ubuntu0.14.04.1

38.*

38.0+build3-0ubuntu0.14.04.1

39.*

39.0+build5-0ubuntu0.14.04.1
39.0.3+build2-0ubuntu0.14.04.1

40.*

40.0+build4-0ubuntu0.14.04.1
40.0+build4-0ubuntu0.14.04.4
40.0.3+build1-0ubuntu0.14.04.1

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "41.0+build3-0ubuntu0.14.04.1",
            "binary_name": "firefox"
        },
        {
            "binary_version": "41.0+build3-0ubuntu0.14.04.1",
            "binary_name": "firefox-dbg"
        },
        {
            "binary_version": "41.0+build3-0ubuntu0.14.04.1",
            "binary_name": "firefox-dbgsym"
        },
        {
            "binary_version": "41.0+build3-0ubuntu0.14.04.1",
            "binary_name": "firefox-dev"
        },
        {
            "binary_version": "41.0+build3-0ubuntu0.14.04.1",
            "binary_name": "firefox-globalmenu"
        },
        {
            "binary_version": "41.0+build3-0ubuntu0.14.04.1",
            "binary_name": "firefox-locale-af"
        },
        {
            "binary_version": "41.0+build3-0ubuntu0.14.04.1",
            "binary_name": "firefox-locale-an"
        },
        {
            "binary_version": "41.0+build3-0ubuntu0.14.04.1",
            "binary_name": "firefox-locale-ar"
        },
        {
            "binary_version": "41.0+build3-0ubuntu0.14.04.1",
            "binary_name": "firefox-locale-as"
        },
        {
            "binary_version": "41.0+build3-0ubuntu0.14.04.1",
            "binary_name": "firefox-locale-ast"
        },
        {
            "binary_version": "41.0+build3-0ubuntu0.14.04.1",
            "binary_name": "firefox-locale-az"
        },
        {
            "binary_version": "41.0+build3-0ubuntu0.14.04.1",
            "binary_name": "firefox-locale-be"
        },
        {
            "binary_version": "41.0+build3-0ubuntu0.14.04.1",
            "binary_name": "firefox-locale-bg"
        },
        {
            "binary_version": "41.0+build3-0ubuntu0.14.04.1",
            "binary_name": "firefox-locale-bn"
        },
        {
            "binary_version": "41.0+build3-0ubuntu0.14.04.1",
            "binary_name": "firefox-locale-br"
        },
        {
            "binary_version": "41.0+build3-0ubuntu0.14.04.1",
            "binary_name": "firefox-locale-bs"
        },
        {
            "binary_version": "41.0+build3-0ubuntu0.14.04.1",
            "binary_name": "firefox-locale-ca"
        },
        {
            "binary_version": "41.0+build3-0ubuntu0.14.04.1",
            "binary_name": "firefox-locale-cs"
        },
        {
            "binary_version": "41.0+build3-0ubuntu0.14.04.1",
            "binary_name": "firefox-locale-csb"
        },
        {
            "binary_version": "41.0+build3-0ubuntu0.14.04.1",
            "binary_name": "firefox-locale-cy"
        },
        {
            "binary_version": "41.0+build3-0ubuntu0.14.04.1",
            "binary_name": "firefox-locale-da"
        },
        {
            "binary_version": "41.0+build3-0ubuntu0.14.04.1",
            "binary_name": "firefox-locale-de"
        },
        {
            "binary_version": "41.0+build3-0ubuntu0.14.04.1",
            "binary_name": "firefox-locale-el"
        },
        {
            "binary_version": "41.0+build3-0ubuntu0.14.04.1",
            "binary_name": "firefox-locale-en"
        },
        {
            "binary_version": "41.0+build3-0ubuntu0.14.04.1",
            "binary_name": "firefox-locale-eo"
        },
        {
            "binary_version": "41.0+build3-0ubuntu0.14.04.1",
            "binary_name": "firefox-locale-es"
        },
        {
            "binary_version": "41.0+build3-0ubuntu0.14.04.1",
            "binary_name": "firefox-locale-et"
        },
        {
            "binary_version": "41.0+build3-0ubuntu0.14.04.1",
            "binary_name": "firefox-locale-eu"
        },
        {
            "binary_version": "41.0+build3-0ubuntu0.14.04.1",
            "binary_name": "firefox-locale-fa"
        },
        {
            "binary_version": "41.0+build3-0ubuntu0.14.04.1",
            "binary_name": "firefox-locale-fi"
        },
        {
            "binary_version": "41.0+build3-0ubuntu0.14.04.1",
            "binary_name": "firefox-locale-fr"
        },
        {
            "binary_version": "41.0+build3-0ubuntu0.14.04.1",
            "binary_name": "firefox-locale-fy"
        },
        {
            "binary_version": "41.0+build3-0ubuntu0.14.04.1",
            "binary_name": "firefox-locale-ga"
        },
        {
            "binary_version": "41.0+build3-0ubuntu0.14.04.1",
            "binary_name": "firefox-locale-gd"
        },
        {
            "binary_version": "41.0+build3-0ubuntu0.14.04.1",
            "binary_name": "firefox-locale-gl"
        },
        {
            "binary_version": "41.0+build3-0ubuntu0.14.04.1",
            "binary_name": "firefox-locale-gu"
        },
        {
            "binary_version": "41.0+build3-0ubuntu0.14.04.1",
            "binary_name": "firefox-locale-he"
        },
        {
            "binary_version": "41.0+build3-0ubuntu0.14.04.1",
            "binary_name": "firefox-locale-hi"
        },
        {
            "binary_version": "41.0+build3-0ubuntu0.14.04.1",
            "binary_name": "firefox-locale-hr"
        },
        {
            "binary_version": "41.0+build3-0ubuntu0.14.04.1",
            "binary_name": "firefox-locale-hsb"
        },
        {
            "binary_version": "41.0+build3-0ubuntu0.14.04.1",
            "binary_name": "firefox-locale-hu"
        },
        {
            "binary_version": "41.0+build3-0ubuntu0.14.04.1",
            "binary_name": "firefox-locale-hy"
        },
        {
            "binary_version": "41.0+build3-0ubuntu0.14.04.1",
            "binary_name": "firefox-locale-id"
        },
        {
            "binary_version": "41.0+build3-0ubuntu0.14.04.1",
            "binary_name": "firefox-locale-is"
        },
        {
            "binary_version": "41.0+build3-0ubuntu0.14.04.1",
            "binary_name": "firefox-locale-it"
        },
        {
            "binary_version": "41.0+build3-0ubuntu0.14.04.1",
            "binary_name": "firefox-locale-ja"
        },
        {
            "binary_version": "41.0+build3-0ubuntu0.14.04.1",
            "binary_name": "firefox-locale-ka"
        },
        {
            "binary_version": "41.0+build3-0ubuntu0.14.04.1",
            "binary_name": "firefox-locale-kk"
        },
        {
            "binary_version": "41.0+build3-0ubuntu0.14.04.1",
            "binary_name": "firefox-locale-km"
        },
        {
            "binary_version": "41.0+build3-0ubuntu0.14.04.1",
            "binary_name": "firefox-locale-kn"
        },
        {
            "binary_version": "41.0+build3-0ubuntu0.14.04.1",
            "binary_name": "firefox-locale-ko"
        },
        {
            "binary_version": "41.0+build3-0ubuntu0.14.04.1",
            "binary_name": "firefox-locale-ku"
        },
        {
            "binary_version": "41.0+build3-0ubuntu0.14.04.1",
            "binary_name": "firefox-locale-lg"
        },
        {
            "binary_version": "41.0+build3-0ubuntu0.14.04.1",
            "binary_name": "firefox-locale-lt"
        },
        {
            "binary_version": "41.0+build3-0ubuntu0.14.04.1",
            "binary_name": "firefox-locale-lv"
        },
        {
            "binary_version": "41.0+build3-0ubuntu0.14.04.1",
            "binary_name": "firefox-locale-mai"
        },
        {
            "binary_version": "41.0+build3-0ubuntu0.14.04.1",
            "binary_name": "firefox-locale-mk"
        },
        {
            "binary_version": "41.0+build3-0ubuntu0.14.04.1",
            "binary_name": "firefox-locale-ml"
        },
        {
            "binary_version": "41.0+build3-0ubuntu0.14.04.1",
            "binary_name": "firefox-locale-mn"
        },
        {
            "binary_version": "41.0+build3-0ubuntu0.14.04.1",
            "binary_name": "firefox-locale-mr"
        },
        {
            "binary_version": "41.0+build3-0ubuntu0.14.04.1",
            "binary_name": "firefox-locale-ms"
        },
        {
            "binary_version": "41.0+build3-0ubuntu0.14.04.1",
            "binary_name": "firefox-locale-nb"
        },
        {
            "binary_version": "41.0+build3-0ubuntu0.14.04.1",
            "binary_name": "firefox-locale-nl"
        },
        {
            "binary_version": "41.0+build3-0ubuntu0.14.04.1",
            "binary_name": "firefox-locale-nn"
        },
        {
            "binary_version": "41.0+build3-0ubuntu0.14.04.1",
            "binary_name": "firefox-locale-nso"
        },
        {
            "binary_version": "41.0+build3-0ubuntu0.14.04.1",
            "binary_name": "firefox-locale-oc"
        },
        {
            "binary_version": "41.0+build3-0ubuntu0.14.04.1",
            "binary_name": "firefox-locale-or"
        },
        {
            "binary_version": "41.0+build3-0ubuntu0.14.04.1",
            "binary_name": "firefox-locale-pa"
        },
        {
            "binary_version": "41.0+build3-0ubuntu0.14.04.1",
            "binary_name": "firefox-locale-pl"
        },
        {
            "binary_version": "41.0+build3-0ubuntu0.14.04.1",
            "binary_name": "firefox-locale-pt"
        },
        {
            "binary_version": "41.0+build3-0ubuntu0.14.04.1",
            "binary_name": "firefox-locale-ro"
        },
        {
            "binary_version": "41.0+build3-0ubuntu0.14.04.1",
            "binary_name": "firefox-locale-ru"
        },
        {
            "binary_version": "41.0+build3-0ubuntu0.14.04.1",
            "binary_name": "firefox-locale-si"
        },
        {
            "binary_version": "41.0+build3-0ubuntu0.14.04.1",
            "binary_name": "firefox-locale-sk"
        },
        {
            "binary_version": "41.0+build3-0ubuntu0.14.04.1",
            "binary_name": "firefox-locale-sl"
        },
        {
            "binary_version": "41.0+build3-0ubuntu0.14.04.1",
            "binary_name": "firefox-locale-sq"
        },
        {
            "binary_version": "41.0+build3-0ubuntu0.14.04.1",
            "binary_name": "firefox-locale-sr"
        },
        {
            "binary_version": "41.0+build3-0ubuntu0.14.04.1",
            "binary_name": "firefox-locale-sv"
        },
        {
            "binary_version": "41.0+build3-0ubuntu0.14.04.1",
            "binary_name": "firefox-locale-sw"
        },
        {
            "binary_version": "41.0+build3-0ubuntu0.14.04.1",
            "binary_name": "firefox-locale-ta"
        },
        {
            "binary_version": "41.0+build3-0ubuntu0.14.04.1",
            "binary_name": "firefox-locale-te"
        },
        {
            "binary_version": "41.0+build3-0ubuntu0.14.04.1",
            "binary_name": "firefox-locale-th"
        },
        {
            "binary_version": "41.0+build3-0ubuntu0.14.04.1",
            "binary_name": "firefox-locale-tr"
        },
        {
            "binary_version": "41.0+build3-0ubuntu0.14.04.1",
            "binary_name": "firefox-locale-uk"
        },
        {
            "binary_version": "41.0+build3-0ubuntu0.14.04.1",
            "binary_name": "firefox-locale-uz"
        },
        {
            "binary_version": "41.0+build3-0ubuntu0.14.04.1",
            "binary_name": "firefox-locale-vi"
        },
        {
            "binary_version": "41.0+build3-0ubuntu0.14.04.1",
            "binary_name": "firefox-locale-xh"
        },
        {
            "binary_version": "41.0+build3-0ubuntu0.14.04.1",
            "binary_name": "firefox-locale-zh-hans"
        },
        {
            "binary_version": "41.0+build3-0ubuntu0.14.04.1",
            "binary_name": "firefox-locale-zh-hant"
        },
        {
            "binary_version": "41.0+build3-0ubuntu0.14.04.1",
            "binary_name": "firefox-locale-zu"
        },
        {
            "binary_version": "41.0+build3-0ubuntu0.14.04.1",
            "binary_name": "firefox-mozsymbols"
        },
        {
            "binary_version": "41.0+build3-0ubuntu0.14.04.1",
            "binary_name": "firefox-testsuite"
        }
    ]
}