USN-2917-3

See a problem?
Source
https://ubuntu.com/security/notices/USN-2917-3
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/USN-2917-3.json
JSON Data
https://api.osv.dev/v1/vulns/USN-2917-3
Published
2016-04-19T14:24:51.979462Z
Modified
2016-04-19T14:24:51.979462Z
Summary
firefox regressions
Details

USN-2917-1 fixed vulnerabilities in Firefox. This update caused several web compatibility regressions.

This update fixes the problem.

We apologize for the inconvenience.

Original advisory details:

Francis Gabriel discovered a buffer overflow during ASN.1 decoding in NSS. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to cause a denial of service via application crash, or execute arbitrary code with the privileges of the user invoking Firefox. (CVE-2016-1950)

Bob Clary, Christoph Diehl, Christian Holler, Andrew McCreight, Daniel Holbert, Jesse Ruderman, Randell Jesup, Carsten Book, Gian-Carlo Pascutto, Tyson Smith, Andrea Marchesini, and Jukka Jylänki discovered multiple memory safety issues in Firefox. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit these to cause a denial of service via application crash, or execute arbitrary code with the privileges of the user invoking Firefox. (CVE-2016-1952, CVE-2016-1953)

Nicolas Golubovic discovered that CSP violation reports can be used to overwrite local files. If a user were tricked in to opening a specially crafted website with addon signing disabled and unpacked addons installed, an attacker could potentially exploit this to gain additional privileges. (CVE-2016-1954)

Muneaki Nishimura discovered that CSP violation reports contained full paths for cross-origin iframe navigations. An attacker could potentially exploit this to steal confidential data. (CVE-2016-1955)

Ucha Gobejishvili discovered that performing certain WebGL operations resulted in memory resource exhaustion with some Intel GPUs, requiring a reboot. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to cause a denial of service. (CVE-2016-1956)

Jose Martinez and Romina Santillan discovered a memory leak in libstagefright during MPEG4 video file processing in some circumstances. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to cause a denial of service via memory exhaustion. (CVE-2016-1957)

Abdulrahman Alqabandi discovered that the addressbar could be blank or filled with page defined content in some circumstances. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to conduct URL spoofing attacks. (CVE-2016-1958)

Looben Yang discovered an out-of-bounds read in Service Worker Manager. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to cause a denial of service via application crash, or execute arbitrary code with the privileges of the user invoking Firefox. (CVE-2016-1959)

A use-after-free was discovered in the HTML5 string parser. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to cause a denial of service via application crash, or execute arbitrary code with the privileges of the user invoking Firefox. (CVE-2016-1960)

A use-after-free was discovered in the SetBody function of HTMLDocument. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to cause a denial of service via application crash, or execute arbitrary code with the privileges of the user invoking Firefox. (CVE-2016-1961)

Dominique Hazaël-Massieux discovered a use-after-free when using multiple WebRTC data channels. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to cause a denial of service via application crash, or execute arbitrary code with the privileges of the user invoking Firefox. (CVE-2016-1962)

It was discovered that Firefox crashes when local files are modified whilst being read by the FileReader API. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to execute arbitrary code with the privileges of the user invoking Firefox. (CVE-2016-1963)

Nicolas Grégoire discovered a use-after-free during XML transformations. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to cause a denial of service via application crash, or execute arbitrary code with the privileges of the user invoking Firefox. (CVE-2016-1964)

Tsubasa Iinuma discovered a mechanism to cause the addressbar to display an incorrect URL, using history navigations and the Location protocol property. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to conduct URL spoofing attacks. (CVE-2016-1965)

A memory corruption issues was discovered in the NPAPI subsystem. If a user were tricked in to opening a specially crafted website with a malicious plugin installed, an attacker could potentially exploit this to cause a denial of service via application crash, or execute arbitrary code with the privileges of the user invoking Firefox. (CVE-2016-1966)

Jordi Chancel discovered a same-origin-policy bypass when using performance.getEntries and history navigation with session restore. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to steal confidential data. (CVE-2016-1967)

Luke Li discovered a buffer overflow during Brotli decompression in some circumstances. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to cause a denial of service via application crash, or execute arbitrary code with the privileges of the user invoking Firefox. (CVE-2016-1968)

Ronald Crane discovered a use-after-free in GetStaticInstance in WebRTC. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to cause a denial of service via application crash, or execute arbitrary code with the privileges of the user invoking Firefox. (CVE-2016-1973)

Ronald Crane discovered an out-of-bounds read following a failed allocation in the HTML parser in some circumstances. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to cause a denial of service via application crash, or execute arbitrary code with the privileges of the user invoking Firefox. (CVE-2016-1974)

Holger Fuhrmannek, Tyson Smith and Holger Fuhrmannek reported multiple memory safety issues in the Graphite 2 library. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit these to cause a denial of service via application crash, or execute arbitrary code with the privileges of the user invoking Firefox. (CVE-2016-1977, CVE-2016-2790, CVE-2016-2791, CVE-2016-2792, CVE-2016-2793, CVE-2016-2794, CVE-2016-2795, CVE-2016-2796, CVE-2016-2797, CVE-2016-2798, CVE-2016-2799, CVE-2016-2800, CVE-2016-2801, CVE-2016-2802)

References

Affected packages

Ubuntu:14.04:LTS / firefox

Package

Name
firefox

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
45.0.2+build1-0ubuntu0.14.04.1

Ecosystem specific

{
    "availability": "No subscription needed",
    "binaries": [
        {
            "firefox-locale-nl": "45.0.2+build1-0ubuntu0.14.04.1",
            "firefox-locale-kn": "45.0.2+build1-0ubuntu0.14.04.1",
            "firefox-locale-gl": "45.0.2+build1-0ubuntu0.14.04.1",
            "firefox-locale-sv": "45.0.2+build1-0ubuntu0.14.04.1",
            "firefox-locale-kk": "45.0.2+build1-0ubuntu0.14.04.1",
            "firefox-locale-fy": "45.0.2+build1-0ubuntu0.14.04.1",
            "firefox-locale-or": "45.0.2+build1-0ubuntu0.14.04.1",
            "firefox-locale-az": "45.0.2+build1-0ubuntu0.14.04.1",
            "firefox-locale-lt": "45.0.2+build1-0ubuntu0.14.04.1",
            "firefox-locale-hy": "45.0.2+build1-0ubuntu0.14.04.1",
            "firefox-locale-eo": "45.0.2+build1-0ubuntu0.14.04.1",
            "firefox-locale-km": "45.0.2+build1-0ubuntu0.14.04.1",
            "firefox-testsuite": "45.0.2+build1-0ubuntu0.14.04.1",
            "firefox-locale-sr": "45.0.2+build1-0ubuntu0.14.04.1",
            "firefox-locale-is": "45.0.2+build1-0ubuntu0.14.04.1",
            "firefox-locale-ca": "45.0.2+build1-0ubuntu0.14.04.1",
            "firefox-locale-uk": "45.0.2+build1-0ubuntu0.14.04.1",
            "firefox-locale-ga": "45.0.2+build1-0ubuntu0.14.04.1",
            "firefox-locale-it": "45.0.2+build1-0ubuntu0.14.04.1",
            "firefox-locale-ja": "45.0.2+build1-0ubuntu0.14.04.1",
            "firefox-locale-lg": "45.0.2+build1-0ubuntu0.14.04.1",
            "firefox-locale-ms": "45.0.2+build1-0ubuntu0.14.04.1",
            "firefox-locale-zh-hans": "45.0.2+build1-0ubuntu0.14.04.1",
            "firefox-mozsymbols": "45.0.2+build1-0ubuntu0.14.04.1",
            "firefox-locale-ko": "45.0.2+build1-0ubuntu0.14.04.1",
            "firefox-locale-hr": "45.0.2+build1-0ubuntu0.14.04.1",
            "firefox-locale-mai": "45.0.2+build1-0ubuntu0.14.04.1",
            "firefox-locale-nb": "45.0.2+build1-0ubuntu0.14.04.1",
            "firefox-dev": "45.0.2+build1-0ubuntu0.14.04.1",
            "firefox-locale-vi": "45.0.2+build1-0ubuntu0.14.04.1",
            "firefox-locale-he": "45.0.2+build1-0ubuntu0.14.04.1",
            "firefox-locale-sw": "45.0.2+build1-0ubuntu0.14.04.1",
            "firefox-locale-el": "45.0.2+build1-0ubuntu0.14.04.1",
            "firefox-locale-oc": "45.0.2+build1-0ubuntu0.14.04.1",
            "firefox-locale-xh": "45.0.2+build1-0ubuntu0.14.04.1",
            "firefox-locale-nn": "45.0.2+build1-0ubuntu0.14.04.1",
            "firefox-locale-zu": "45.0.2+build1-0ubuntu0.14.04.1",
            "firefox-locale-ar": "45.0.2+build1-0ubuntu0.14.04.1",
            "firefox-locale-cs": "45.0.2+build1-0ubuntu0.14.04.1",
            "firefox-locale-gn": "45.0.2+build1-0ubuntu0.14.04.1",
            "firefox-locale-hsb": "45.0.2+build1-0ubuntu0.14.04.1",
            "firefox-locale-csb": "45.0.2+build1-0ubuntu0.14.04.1",
            "firefox-locale-ro": "45.0.2+build1-0ubuntu0.14.04.1",
            "firefox-globalmenu": "45.0.2+build1-0ubuntu0.14.04.1",
            "firefox-locale-af": "45.0.2+build1-0ubuntu0.14.04.1",
            "firefox-locale-nso": "45.0.2+build1-0ubuntu0.14.04.1",
            "firefox-locale-sk": "45.0.2+build1-0ubuntu0.14.04.1",
            "firefox-locale-si": "45.0.2+build1-0ubuntu0.14.04.1",
            "firefox": "45.0.2+build1-0ubuntu0.14.04.1",
            "firefox-locale-cy": "45.0.2+build1-0ubuntu0.14.04.1",
            "firefox-locale-fa": "45.0.2+build1-0ubuntu0.14.04.1",
            "firefox-locale-mn": "45.0.2+build1-0ubuntu0.14.04.1",
            "firefox-locale-sq": "45.0.2+build1-0ubuntu0.14.04.1",
            "firefox-locale-en": "45.0.2+build1-0ubuntu0.14.04.1",
            "firefox-locale-tr": "45.0.2+build1-0ubuntu0.14.04.1",
            "firefox-locale-br": "45.0.2+build1-0ubuntu0.14.04.1",
            "firefox-locale-et": "45.0.2+build1-0ubuntu0.14.04.1",
            "firefox-locale-ast": "45.0.2+build1-0ubuntu0.14.04.1",
            "firefox-locale-th": "45.0.2+build1-0ubuntu0.14.04.1",
            "firefox-locale-da": "45.0.2+build1-0ubuntu0.14.04.1",
            "firefox-locale-fi": "45.0.2+build1-0ubuntu0.14.04.1",
            "firefox-locale-ku": "45.0.2+build1-0ubuntu0.14.04.1",
            "firefox-locale-ru": "45.0.2+build1-0ubuntu0.14.04.1",
            "firefox-locale-mk": "45.0.2+build1-0ubuntu0.14.04.1",
            "firefox-locale-bg": "45.0.2+build1-0ubuntu0.14.04.1",
            "firefox-locale-hu": "45.0.2+build1-0ubuntu0.14.04.1",
            "firefox-locale-gu": "45.0.2+build1-0ubuntu0.14.04.1",
            "firefox-locale-bn": "45.0.2+build1-0ubuntu0.14.04.1",
            "firefox-locale-ml": "45.0.2+build1-0ubuntu0.14.04.1",
            "firefox-locale-an": "45.0.2+build1-0ubuntu0.14.04.1",
            "firefox-locale-be": "45.0.2+build1-0ubuntu0.14.04.1",
            "firefox-locale-eu": "45.0.2+build1-0ubuntu0.14.04.1",
            "firefox-locale-fr": "45.0.2+build1-0ubuntu0.14.04.1",
            "firefox-locale-pa": "45.0.2+build1-0ubuntu0.14.04.1",
            "firefox-locale-as": "45.0.2+build1-0ubuntu0.14.04.1",
            "firefox-locale-lv": "45.0.2+build1-0ubuntu0.14.04.1",
            "firefox-locale-pl": "45.0.2+build1-0ubuntu0.14.04.1",
            "firefox-locale-gd": "45.0.2+build1-0ubuntu0.14.04.1",
            "firefox-locale-te": "45.0.2+build1-0ubuntu0.14.04.1",
            "firefox-locale-ta": "45.0.2+build1-0ubuntu0.14.04.1",
            "firefox-locale-ka": "45.0.2+build1-0ubuntu0.14.04.1",
            "firefox-locale-id": "45.0.2+build1-0ubuntu0.14.04.1",
            "firefox-locale-bs": "45.0.2+build1-0ubuntu0.14.04.1",
            "firefox-locale-hi": "45.0.2+build1-0ubuntu0.14.04.1",
            "firefox-locale-zh-hant": "45.0.2+build1-0ubuntu0.14.04.1",
            "firefox-locale-mr": "45.0.2+build1-0ubuntu0.14.04.1",
            "firefox-locale-es": "45.0.2+build1-0ubuntu0.14.04.1",
            "firefox-locale-sl": "45.0.2+build1-0ubuntu0.14.04.1",
            "firefox-locale-uz": "45.0.2+build1-0ubuntu0.14.04.1",
            "firefox-locale-pt": "45.0.2+build1-0ubuntu0.14.04.1",
            "firefox-locale-de": "45.0.2+build1-0ubuntu0.14.04.1"
        }
    ]
}