USN-5726-1

Source
https://ubuntu.com/security/notices/USN-5726-1
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/USN-5726-1.json
Related
  • CVE-2022-40674
  • CVE-2022-45403
  • CVE-2022-45404
  • CVE-2022-45405
  • CVE-2022-45406
  • CVE-2022-45407
  • CVE-2022-45408
  • CVE-2022-45409
  • CVE-2022-45410
  • CVE-2022-45411
  • CVE-2022-45412
  • CVE-2022-45413
  • CVE-2022-45415
  • CVE-2022-45416
  • CVE-2022-45417
  • CVE-2022-45418
  • CVE-2022-45419
  • CVE-2022-45420
  • CVE-2022-45421
Published
2022-11-16T13:25:42.343768Z
Modified
2022-11-16T13:25:42.343768Z
Details

Multiple security issues were discovered in Firefox. If a user were tricked into opening a specially crafted website, an attacker could potentially exploit these to cause a denial of service, spoof the contents of the addressbar, bypass security restrictions, cross-site tracing or execute arbitrary code. (CVE-2022-45403, CVE-2022-45404, CVE-2022-45405, CVE-2022-45406, CVE-2022-45407, CVE-2022-45408, CVE-2022-45409, CVE-2022-45410, CVE-2022-45411, CVE-2022-45413, CVE-2022-40674, CVE-2022-45418, CVE-2022-45419, CVE-2022-45420, CVE-2022-45421)

Armin Ebert discovered that Firefox did not properly manage while resolving file symlink. If a user were tricked into opening a specially crafted weblink, an attacker could potentially exploit these to cause a denial of service. (CVE-2022-45412)

Jefferson Scher and Jayateertha Guruprasad discovered that Firefox did not properly sanitize the HTML download file extension under certain circumstances. If a user were tricked into downloading and executing malicious content, a remote attacker could execute arbitrary code with the privileges of the user invoking the programs. (CVE-2022-45415)

Erik Kraft, Martin Schwarzl, and Andrew McCreight discovered that Firefox incorrectly handled keyboard events. An attacker could possibly use this issue to perform a timing side-channel attack and possibly figure out which keys are being pressed. (CVE-2022-45416)

Kagami discovered that Firefox did not detect Private Browsing Mode correctly. An attacker could possibly use this issue to obtain sensitive information about Private Browsing Mode. (CVE-2022-45417)

References

Affected packages

Ubuntu:18.04:LTS / firefox

Package

Name
firefox

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0The exact introduced commit is unknown
Fixed
107.0+build2-0ubuntu0.18.04.1

Ecosystem specific

{
    "availability": "No subscription needed",
    "binaries": [
        {
            "firefox-locale-sl": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-nl": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-kn": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-gl": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-fy": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-kk": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-km": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-or": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-az": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-lt": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-hy": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-eo": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-sv": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-uk": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-sr": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-is": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-ca": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-ne": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-ga": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-ja": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-it": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-lg": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-ms": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-zh-hans": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-ia": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-ko": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-hr": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-mai": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-nb": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-mozsymbols": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-vi": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-dev": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-he": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-sw": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-el": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-oc": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-xh": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-nn": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-geckodriver": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-ar": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-cs": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-gn": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-hsb": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-zu": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-my": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-ro": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-csb": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-nso": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-af": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-sk": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-szl": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-si": "107.0+build2-0ubuntu0.18.04.1",
            "firefox": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-cy": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-fa": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-cak": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-sq": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-en": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-tr": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-br": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-et": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-ast": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-th": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-da": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-fi": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-ku": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-mn": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-ru": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-mk": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-bg": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-hu": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-gu": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-bn": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-kab": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-ml": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-an": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-be": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-eu": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-fr": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-pa": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-as": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-id": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-pl": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-gd": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-te": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-lv": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-ka": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-ta": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-bs": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-uz": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-hi": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-zh-hant": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-es": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-ur": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-mr": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-pt": "107.0+build2-0ubuntu0.18.04.1",
            "firefox-locale-de": "107.0+build2-0ubuntu0.18.04.1"
        }
    ]
}

Ubuntu:20.04:LTS / firefox

Package

Name
firefox

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0The exact introduced commit is unknown
Fixed
107.0+build2-0ubuntu0.20.04.1

Ecosystem specific

{
    "availability": "No subscription needed",
    "binaries": [
        {
            "firefox-locale-sl": "107.0+build2-0ubuntu0.20.04.1",
            "firefox-locale-nl": "107.0+build2-0ubuntu0.20.04.1",
            "firefox-locale-kn": "107.0+build2-0ubuntu0.20.04.1",
            "firefox-locale-gl": "107.0+build2-0ubuntu0.20.04.1",
            "firefox-locale-fy": "107.0+build2-0ubuntu0.20.04.1",
            "firefox-locale-kk": "107.0+build2-0ubuntu0.20.04.1",
            "firefox-locale-km": "107.0+build2-0ubuntu0.20.04.1",
            "firefox-locale-or": "107.0+build2-0ubuntu0.20.04.1",
            "firefox-locale-az": "107.0+build2-0ubuntu0.20.04.1",
            "firefox-locale-lt": "107.0+build2-0ubuntu0.20.04.1",
            "firefox-locale-hy": "107.0+build2-0ubuntu0.20.04.1",
            "firefox-locale-eo": "107.0+build2-0ubuntu0.20.04.1",
            "firefox-locale-sv": "107.0+build2-0ubuntu0.20.04.1",
            "firefox-locale-uk": "107.0+build2-0ubuntu0.20.04.1",
            "firefox-locale-sr": "107.0+build2-0ubuntu0.20.04.1",
            "firefox-locale-is": "107.0+build2-0ubuntu0.20.04.1",
            "firefox-locale-ca": "107.0+build2-0ubuntu0.20.04.1",
            "firefox-locale-ne": "107.0+build2-0ubuntu0.20.04.1",
            "firefox-locale-ga": "107.0+build2-0ubuntu0.20.04.1",
            "firefox-locale-ja": "107.0+build2-0ubuntu0.20.04.1",
            "firefox-locale-it": "107.0+build2-0ubuntu0.20.04.1",
            "firefox-locale-lg": "107.0+build2-0ubuntu0.20.04.1",
            "firefox-locale-ms": "107.0+build2-0ubuntu0.20.04.1",
            "firefox-locale-zh-hans": "107.0+build2-0ubuntu0.20.04.1",
            "firefox-locale-ia": "107.0+build2-0ubuntu0.20.04.1",
            "firefox-locale-ko": "107.0+build2-0ubuntu0.20.04.1",
            "firefox-locale-hr": "107.0+build2-0ubuntu0.20.04.1",
            "firefox-locale-mai": "107.0+build2-0ubuntu0.20.04.1",
            "firefox-locale-nb": "107.0+build2-0ubuntu0.20.04.1",
            "firefox-mozsymbols": "107.0+build2-0ubuntu0.20.04.1",
            "firefox-locale-vi": "107.0+build2-0ubuntu0.20.04.1",
            "firefox-dev": "107.0+build2-0ubuntu0.20.04.1",
            "firefox-locale-he": "107.0+build2-0ubuntu0.20.04.1",
            "firefox-locale-sw": "107.0+build2-0ubuntu0.20.04.1",
            "firefox-locale-el": "107.0+build2-0ubuntu0.20.04.1",
            "firefox-locale-oc": "107.0+build2-0ubuntu0.20.04.1",
            "firefox-locale-xh": "107.0+build2-0ubuntu0.20.04.1",
            "firefox-locale-nn": "107.0+build2-0ubuntu0.20.04.1",
            "firefox-geckodriver": "107.0+build2-0ubuntu0.20.04.1",
            "firefox-locale-ar": "107.0+build2-0ubuntu0.20.04.1",
            "firefox-locale-cs": "107.0+build2-0ubuntu0.20.04.1",
            "firefox-locale-gn": "107.0+build2-0ubuntu0.20.04.1",
            "firefox-locale-hsb": "107.0+build2-0ubuntu0.20.04.1",
            "firefox-locale-zu": "107.0+build2-0ubuntu0.20.04.1",
            "firefox-locale-my": "107.0+build2-0ubuntu0.20.04.1",
            "firefox-locale-ro": "107.0+build2-0ubuntu0.20.04.1",
            "firefox-locale-csb": "107.0+build2-0ubuntu0.20.04.1",
            "firefox-locale-nso": "107.0+build2-0ubuntu0.20.04.1",
            "firefox-locale-af": "107.0+build2-0ubuntu0.20.04.1",
            "firefox-locale-sk": "107.0+build2-0ubuntu0.20.04.1",
            "firefox-locale-szl": "107.0+build2-0ubuntu0.20.04.1",
            "firefox-locale-si": "107.0+build2-0ubuntu0.20.04.1",
            "firefox": "107.0+build2-0ubuntu0.20.04.1",
            "firefox-locale-cy": "107.0+build2-0ubuntu0.20.04.1",
            "firefox-locale-fa": "107.0+build2-0ubuntu0.20.04.1",
            "firefox-locale-cak": "107.0+build2-0ubuntu0.20.04.1",
            "firefox-locale-sq": "107.0+build2-0ubuntu0.20.04.1",
            "firefox-locale-en": "107.0+build2-0ubuntu0.20.04.1",
            "firefox-locale-tr": "107.0+build2-0ubuntu0.20.04.1",
            "firefox-locale-br": "107.0+build2-0ubuntu0.20.04.1",
            "firefox-locale-et": "107.0+build2-0ubuntu0.20.04.1",
            "firefox-locale-ast": "107.0+build2-0ubuntu0.20.04.1",
            "firefox-locale-th": "107.0+build2-0ubuntu0.20.04.1",
            "firefox-locale-da": "107.0+build2-0ubuntu0.20.04.1",
            "firefox-locale-fi": "107.0+build2-0ubuntu0.20.04.1",
            "firefox-locale-ku": "107.0+build2-0ubuntu0.20.04.1",
            "firefox-locale-mn": "107.0+build2-0ubuntu0.20.04.1",
            "firefox-locale-ru": "107.0+build2-0ubuntu0.20.04.1",
            "firefox-locale-mk": "107.0+build2-0ubuntu0.20.04.1",
            "firefox-locale-bg": "107.0+build2-0ubuntu0.20.04.1",
            "firefox-locale-hu": "107.0+build2-0ubuntu0.20.04.1",
            "firefox-locale-gu": "107.0+build2-0ubuntu0.20.04.1",
            "firefox-locale-bn": "107.0+build2-0ubuntu0.20.04.1",
            "firefox-locale-kab": "107.0+build2-0ubuntu0.20.04.1",
            "firefox-locale-ml": "107.0+build2-0ubuntu0.20.04.1",
            "firefox-locale-an": "107.0+build2-0ubuntu0.20.04.1",
            "firefox-locale-be": "107.0+build2-0ubuntu0.20.04.1",
            "firefox-locale-eu": "107.0+build2-0ubuntu0.20.04.1",
            "firefox-locale-fr": "107.0+build2-0ubuntu0.20.04.1",
            "firefox-locale-pa": "107.0+build2-0ubuntu0.20.04.1",
            "firefox-locale-as": "107.0+build2-0ubuntu0.20.04.1",
            "firefox-locale-id": "107.0+build2-0ubuntu0.20.04.1",
            "firefox-locale-pl": "107.0+build2-0ubuntu0.20.04.1",
            "firefox-locale-gd": "107.0+build2-0ubuntu0.20.04.1",
            "firefox-locale-te": "107.0+build2-0ubuntu0.20.04.1",
            "firefox-locale-lv": "107.0+build2-0ubuntu0.20.04.1",
            "firefox-locale-ka": "107.0+build2-0ubuntu0.20.04.1",
            "firefox-locale-ta": "107.0+build2-0ubuntu0.20.04.1",
            "firefox-locale-bs": "107.0+build2-0ubuntu0.20.04.1",
            "firefox-locale-uz": "107.0+build2-0ubuntu0.20.04.1",
            "firefox-locale-hi": "107.0+build2-0ubuntu0.20.04.1",
            "firefox-locale-zh-hant": "107.0+build2-0ubuntu0.20.04.1",
            "firefox-locale-es": "107.0+build2-0ubuntu0.20.04.1",
            "firefox-locale-ur": "107.0+build2-0ubuntu0.20.04.1",
            "firefox-locale-mr": "107.0+build2-0ubuntu0.20.04.1",
            "firefox-locale-pt": "107.0+build2-0ubuntu0.20.04.1",
            "firefox-locale-de": "107.0+build2-0ubuntu0.20.04.1"
        }
    ]
}