USN-3596-1

See a problem?
Source
https://ubuntu.com/security/notices/USN-3596-1
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/USN-3596-1.json
JSON Data
https://api.osv.dev/v1/vulns/USN-3596-1
Related
  • CVE-2018-5125
  • CVE-2018-5126
  • CVE-2018-5127
  • CVE-2018-5128
  • CVE-2018-5129
  • CVE-2018-5130
  • CVE-2018-5131
  • CVE-2018-5132
  • CVE-2018-5133
  • CVE-2018-5134
  • CVE-2018-5135
  • CVE-2018-5136
  • CVE-2018-5137
  • CVE-2018-5140
  • CVE-2018-5141
  • CVE-2018-5142
  • CVE-2018-5143
Published
2018-03-14T21:56:40.418811Z
Modified
2018-03-14T21:56:40.418811Z
Summary
firefox vulnerabilities
Details

Multiple security issues were discovered in Firefox. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit these to cause a denial of service via application crash or opening new tabs, escape the sandbox, bypass same-origin restrictions, obtain sensitive information, confuse the user with misleading permission requests, or execute arbitrary code. (CVE-2018-5125, CVE-2018-5126, CVE-2018-5127, CVE-2018-5128, CVE-2018-5129, CVE-2018-5130, CVE-2018-5136, CVE-2018-5137, CVE-2018-5140, CVE-2018-5141, CVE-2018-5142)

It was discovered that the fetch() API could incorrectly return cached copies of no-store/no-cache resources in some circumstances. A local attacker could potentially exploit this to obtain sensitive information in environments where multiple users share a common profile. (CVE-2018-5131)

Multiple security issues were discovered with WebExtensions. If a user were tricked in to installing a specially crafted extension, an attacker could potentially exploit these to obtain sensitive information or bypass security restrictions. (CVE-2018-5132, CVE-2018-5134, CVE-2018-5135)

It was discovered that the value of app.support.baseURL is not sanitized properly. If a malicious local application were to set this to a specially crafted value, an attacker could potentially exploit this to execute arbitrary code. (CVE-2018-5133)

It was discovered that javascript: URLs with embedded tab characters could be pasted in to the addressbar. If a user were tricked in to copying a specially crafted URL in to the addressbar, an attacker could exploit this to conduct cross-site scripting (XSS) attacks. (CVE-2018-5143)

References

Affected packages

Ubuntu:14.04:LTS / firefox

Package

Name
firefox

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
59.0+build5-0ubuntu0.14.04.1

Ecosystem specific

{
    "availability": "No subscription needed",
    "binaries": [
        {
            "firefox-locale-sl": "59.0+build5-0ubuntu0.14.04.1",
            "firefox-locale-nl": "59.0+build5-0ubuntu0.14.04.1",
            "firefox-locale-kn": "59.0+build5-0ubuntu0.14.04.1",
            "firefox-locale-gl": "59.0+build5-0ubuntu0.14.04.1",
            "firefox-locale-fy": "59.0+build5-0ubuntu0.14.04.1",
            "firefox-locale-kk": "59.0+build5-0ubuntu0.14.04.1",
            "firefox-locale-km": "59.0+build5-0ubuntu0.14.04.1",
            "firefox-locale-or": "59.0+build5-0ubuntu0.14.04.1",
            "firefox-locale-az": "59.0+build5-0ubuntu0.14.04.1",
            "firefox-locale-lt": "59.0+build5-0ubuntu0.14.04.1",
            "firefox-locale-hy": "59.0+build5-0ubuntu0.14.04.1",
            "firefox-locale-eo": "59.0+build5-0ubuntu0.14.04.1",
            "firefox-locale-sv": "59.0+build5-0ubuntu0.14.04.1",
            "firefox-testsuite": "59.0+build5-0ubuntu0.14.04.1",
            "firefox-locale-sr": "59.0+build5-0ubuntu0.14.04.1",
            "firefox-locale-is": "59.0+build5-0ubuntu0.14.04.1",
            "firefox-locale-ca": "59.0+build5-0ubuntu0.14.04.1",
            "firefox-locale-uk": "59.0+build5-0ubuntu0.14.04.1",
            "firefox-locale-ne": "59.0+build5-0ubuntu0.14.04.1",
            "firefox-locale-ga": "59.0+build5-0ubuntu0.14.04.1",
            "firefox-locale-it": "59.0+build5-0ubuntu0.14.04.1",
            "firefox-locale-ja": "59.0+build5-0ubuntu0.14.04.1",
            "firefox-locale-lg": "59.0+build5-0ubuntu0.14.04.1",
            "firefox-locale-ms": "59.0+build5-0ubuntu0.14.04.1",
            "firefox-locale-zh-hans": "59.0+build5-0ubuntu0.14.04.1",
            "firefox-locale-ia": "59.0+build5-0ubuntu0.14.04.1",
            "firefox-locale-ko": "59.0+build5-0ubuntu0.14.04.1",
            "firefox-locale-hr": "59.0+build5-0ubuntu0.14.04.1",
            "firefox-locale-mai": "59.0+build5-0ubuntu0.14.04.1",
            "firefox-locale-nb": "59.0+build5-0ubuntu0.14.04.1",
            "firefox-mozsymbols": "59.0+build5-0ubuntu0.14.04.1",
            "firefox-locale-vi": "59.0+build5-0ubuntu0.14.04.1",
            "firefox-dev": "59.0+build5-0ubuntu0.14.04.1",
            "firefox-locale-he": "59.0+build5-0ubuntu0.14.04.1",
            "firefox-locale-sw": "59.0+build5-0ubuntu0.14.04.1",
            "firefox-locale-el": "59.0+build5-0ubuntu0.14.04.1",
            "firefox-locale-oc": "59.0+build5-0ubuntu0.14.04.1",
            "firefox-locale-xh": "59.0+build5-0ubuntu0.14.04.1",
            "firefox-locale-nn": "59.0+build5-0ubuntu0.14.04.1",
            "firefox-locale-ar": "59.0+build5-0ubuntu0.14.04.1",
            "firefox-locale-csb": "59.0+build5-0ubuntu0.14.04.1",
            "firefox-locale-cs": "59.0+build5-0ubuntu0.14.04.1",
            "firefox-locale-gn": "59.0+build5-0ubuntu0.14.04.1",
            "firefox-locale-hsb": "59.0+build5-0ubuntu0.14.04.1",
            "firefox-locale-zu": "59.0+build5-0ubuntu0.14.04.1",
            "firefox-locale-my": "59.0+build5-0ubuntu0.14.04.1",
            "firefox-locale-ro": "59.0+build5-0ubuntu0.14.04.1",
            "firefox-globalmenu": "59.0+build5-0ubuntu0.14.04.1",
            "firefox-locale-nso": "59.0+build5-0ubuntu0.14.04.1",
            "firefox-locale-af": "59.0+build5-0ubuntu0.14.04.1",
            "firefox-locale-sk": "59.0+build5-0ubuntu0.14.04.1",
            "firefox-locale-si": "59.0+build5-0ubuntu0.14.04.1",
            "firefox": "59.0+build5-0ubuntu0.14.04.1",
            "firefox-locale-cy": "59.0+build5-0ubuntu0.14.04.1",
            "firefox-locale-fa": "59.0+build5-0ubuntu0.14.04.1",
            "firefox-locale-cak": "59.0+build5-0ubuntu0.14.04.1",
            "firefox-locale-sq": "59.0+build5-0ubuntu0.14.04.1",
            "firefox-locale-en": "59.0+build5-0ubuntu0.14.04.1",
            "firefox-locale-tr": "59.0+build5-0ubuntu0.14.04.1",
            "firefox-locale-br": "59.0+build5-0ubuntu0.14.04.1",
            "firefox-locale-et": "59.0+build5-0ubuntu0.14.04.1",
            "firefox-locale-ast": "59.0+build5-0ubuntu0.14.04.1",
            "firefox-locale-th": "59.0+build5-0ubuntu0.14.04.1",
            "firefox-locale-da": "59.0+build5-0ubuntu0.14.04.1",
            "firefox-locale-fi": "59.0+build5-0ubuntu0.14.04.1",
            "firefox-locale-ku": "59.0+build5-0ubuntu0.14.04.1",
            "firefox-locale-mn": "59.0+build5-0ubuntu0.14.04.1",
            "firefox-locale-ru": "59.0+build5-0ubuntu0.14.04.1",
            "firefox-locale-mk": "59.0+build5-0ubuntu0.14.04.1",
            "firefox-locale-bg": "59.0+build5-0ubuntu0.14.04.1",
            "firefox-locale-hu": "59.0+build5-0ubuntu0.14.04.1",
            "firefox-locale-gu": "59.0+build5-0ubuntu0.14.04.1",
            "firefox-locale-bn": "59.0+build5-0ubuntu0.14.04.1",
            "firefox-locale-kab": "59.0+build5-0ubuntu0.14.04.1",
            "firefox-locale-ml": "59.0+build5-0ubuntu0.14.04.1",
            "firefox-locale-an": "59.0+build5-0ubuntu0.14.04.1",
            "firefox-locale-be": "59.0+build5-0ubuntu0.14.04.1",
            "firefox-locale-eu": "59.0+build5-0ubuntu0.14.04.1",
            "firefox-locale-fr": "59.0+build5-0ubuntu0.14.04.1",
            "firefox-locale-pa": "59.0+build5-0ubuntu0.14.04.1",
            "firefox-locale-as": "59.0+build5-0ubuntu0.14.04.1",
            "firefox-locale-ta": "59.0+build5-0ubuntu0.14.04.1",
            "firefox-locale-pl": "59.0+build5-0ubuntu0.14.04.1",
            "firefox-locale-bs": "59.0+build5-0ubuntu0.14.04.1",
            "firefox-locale-te": "59.0+build5-0ubuntu0.14.04.1",
            "firefox-locale-id": "59.0+build5-0ubuntu0.14.04.1",
            "firefox-locale-ka": "59.0+build5-0ubuntu0.14.04.1",
            "firefox-locale-lv": "59.0+build5-0ubuntu0.14.04.1",
            "firefox-locale-gd": "59.0+build5-0ubuntu0.14.04.1",
            "firefox-locale-uz": "59.0+build5-0ubuntu0.14.04.1",
            "firefox-locale-zh-hant": "59.0+build5-0ubuntu0.14.04.1",
            "firefox-locale-hi": "59.0+build5-0ubuntu0.14.04.1",
            "firefox-locale-es": "59.0+build5-0ubuntu0.14.04.1",
            "firefox-locale-de": "59.0+build5-0ubuntu0.14.04.1",
            "firefox-locale-mr": "59.0+build5-0ubuntu0.14.04.1",
            "firefox-locale-pt": "59.0+build5-0ubuntu0.14.04.1",
            "firefox-locale-ur": "59.0+build5-0ubuntu0.14.04.1"
        }
    ]
}

Ubuntu:16.04:LTS / firefox

Package

Name
firefox

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
59.0+build5-0ubuntu0.16.04.1

Ecosystem specific

{
    "availability": "No subscription needed",
    "binaries": [
        {
            "firefox-locale-sl": "59.0+build5-0ubuntu0.16.04.1",
            "firefox-locale-nl": "59.0+build5-0ubuntu0.16.04.1",
            "firefox-locale-kn": "59.0+build5-0ubuntu0.16.04.1",
            "firefox-locale-gl": "59.0+build5-0ubuntu0.16.04.1",
            "firefox-locale-fy": "59.0+build5-0ubuntu0.16.04.1",
            "firefox-locale-kk": "59.0+build5-0ubuntu0.16.04.1",
            "firefox-locale-km": "59.0+build5-0ubuntu0.16.04.1",
            "firefox-locale-or": "59.0+build5-0ubuntu0.16.04.1",
            "firefox-locale-az": "59.0+build5-0ubuntu0.16.04.1",
            "firefox-locale-lt": "59.0+build5-0ubuntu0.16.04.1",
            "firefox-locale-hy": "59.0+build5-0ubuntu0.16.04.1",
            "firefox-locale-eo": "59.0+build5-0ubuntu0.16.04.1",
            "firefox-locale-sv": "59.0+build5-0ubuntu0.16.04.1",
            "firefox-testsuite": "59.0+build5-0ubuntu0.16.04.1",
            "firefox-locale-sr": "59.0+build5-0ubuntu0.16.04.1",
            "firefox-locale-is": "59.0+build5-0ubuntu0.16.04.1",
            "firefox-locale-ca": "59.0+build5-0ubuntu0.16.04.1",
            "firefox-locale-uk": "59.0+build5-0ubuntu0.16.04.1",
            "firefox-locale-ne": "59.0+build5-0ubuntu0.16.04.1",
            "firefox-locale-ga": "59.0+build5-0ubuntu0.16.04.1",
            "firefox-locale-it": "59.0+build5-0ubuntu0.16.04.1",
            "firefox-locale-ja": "59.0+build5-0ubuntu0.16.04.1",
            "firefox-locale-lg": "59.0+build5-0ubuntu0.16.04.1",
            "firefox-locale-ms": "59.0+build5-0ubuntu0.16.04.1",
            "firefox-locale-zh-hans": "59.0+build5-0ubuntu0.16.04.1",
            "firefox-locale-ia": "59.0+build5-0ubuntu0.16.04.1",
            "firefox-locale-ko": "59.0+build5-0ubuntu0.16.04.1",
            "firefox-locale-hr": "59.0+build5-0ubuntu0.16.04.1",
            "firefox-locale-mai": "59.0+build5-0ubuntu0.16.04.1",
            "firefox-locale-nb": "59.0+build5-0ubuntu0.16.04.1",
            "firefox-mozsymbols": "59.0+build5-0ubuntu0.16.04.1",
            "firefox-locale-vi": "59.0+build5-0ubuntu0.16.04.1",
            "firefox-dev": "59.0+build5-0ubuntu0.16.04.1",
            "firefox-locale-he": "59.0+build5-0ubuntu0.16.04.1",
            "firefox-locale-sw": "59.0+build5-0ubuntu0.16.04.1",
            "firefox-locale-el": "59.0+build5-0ubuntu0.16.04.1",
            "firefox-locale-oc": "59.0+build5-0ubuntu0.16.04.1",
            "firefox-locale-xh": "59.0+build5-0ubuntu0.16.04.1",
            "firefox-locale-nn": "59.0+build5-0ubuntu0.16.04.1",
            "firefox-locale-ar": "59.0+build5-0ubuntu0.16.04.1",
            "firefox-locale-csb": "59.0+build5-0ubuntu0.16.04.1",
            "firefox-locale-cs": "59.0+build5-0ubuntu0.16.04.1",
            "firefox-locale-gn": "59.0+build5-0ubuntu0.16.04.1",
            "firefox-locale-hsb": "59.0+build5-0ubuntu0.16.04.1",
            "firefox-locale-zu": "59.0+build5-0ubuntu0.16.04.1",
            "firefox-locale-my": "59.0+build5-0ubuntu0.16.04.1",
            "firefox-locale-ro": "59.0+build5-0ubuntu0.16.04.1",
            "firefox-globalmenu": "59.0+build5-0ubuntu0.16.04.1",
            "firefox-locale-nso": "59.0+build5-0ubuntu0.16.04.1",
            "firefox-locale-af": "59.0+build5-0ubuntu0.16.04.1",
            "firefox-locale-sk": "59.0+build5-0ubuntu0.16.04.1",
            "firefox-locale-si": "59.0+build5-0ubuntu0.16.04.1",
            "firefox": "59.0+build5-0ubuntu0.16.04.1",
            "firefox-locale-cy": "59.0+build5-0ubuntu0.16.04.1",
            "firefox-locale-fa": "59.0+build5-0ubuntu0.16.04.1",
            "firefox-locale-cak": "59.0+build5-0ubuntu0.16.04.1",
            "firefox-locale-sq": "59.0+build5-0ubuntu0.16.04.1",
            "firefox-locale-en": "59.0+build5-0ubuntu0.16.04.1",
            "firefox-locale-tr": "59.0+build5-0ubuntu0.16.04.1",
            "firefox-locale-br": "59.0+build5-0ubuntu0.16.04.1",
            "firefox-locale-et": "59.0+build5-0ubuntu0.16.04.1",
            "firefox-locale-ast": "59.0+build5-0ubuntu0.16.04.1",
            "firefox-locale-th": "59.0+build5-0ubuntu0.16.04.1",
            "firefox-locale-da": "59.0+build5-0ubuntu0.16.04.1",
            "firefox-locale-fi": "59.0+build5-0ubuntu0.16.04.1",
            "firefox-locale-ku": "59.0+build5-0ubuntu0.16.04.1",
            "firefox-locale-mn": "59.0+build5-0ubuntu0.16.04.1",
            "firefox-locale-ru": "59.0+build5-0ubuntu0.16.04.1",
            "firefox-locale-mk": "59.0+build5-0ubuntu0.16.04.1",
            "firefox-locale-bg": "59.0+build5-0ubuntu0.16.04.1",
            "firefox-locale-hu": "59.0+build5-0ubuntu0.16.04.1",
            "firefox-locale-gu": "59.0+build5-0ubuntu0.16.04.1",
            "firefox-locale-bn": "59.0+build5-0ubuntu0.16.04.1",
            "firefox-locale-kab": "59.0+build5-0ubuntu0.16.04.1",
            "firefox-locale-ml": "59.0+build5-0ubuntu0.16.04.1",
            "firefox-locale-an": "59.0+build5-0ubuntu0.16.04.1",
            "firefox-locale-be": "59.0+build5-0ubuntu0.16.04.1",
            "firefox-locale-eu": "59.0+build5-0ubuntu0.16.04.1",
            "firefox-locale-fr": "59.0+build5-0ubuntu0.16.04.1",
            "firefox-locale-pa": "59.0+build5-0ubuntu0.16.04.1",
            "firefox-locale-as": "59.0+build5-0ubuntu0.16.04.1",
            "firefox-locale-ta": "59.0+build5-0ubuntu0.16.04.1",
            "firefox-locale-pl": "59.0+build5-0ubuntu0.16.04.1",
            "firefox-locale-bs": "59.0+build5-0ubuntu0.16.04.1",
            "firefox-locale-te": "59.0+build5-0ubuntu0.16.04.1",
            "firefox-locale-id": "59.0+build5-0ubuntu0.16.04.1",
            "firefox-locale-ka": "59.0+build5-0ubuntu0.16.04.1",
            "firefox-locale-lv": "59.0+build5-0ubuntu0.16.04.1",
            "firefox-locale-gd": "59.0+build5-0ubuntu0.16.04.1",
            "firefox-locale-uz": "59.0+build5-0ubuntu0.16.04.1",
            "firefox-locale-zh-hant": "59.0+build5-0ubuntu0.16.04.1",
            "firefox-locale-hi": "59.0+build5-0ubuntu0.16.04.1",
            "firefox-locale-es": "59.0+build5-0ubuntu0.16.04.1",
            "firefox-locale-de": "59.0+build5-0ubuntu0.16.04.1",
            "firefox-locale-mr": "59.0+build5-0ubuntu0.16.04.1",
            "firefox-locale-pt": "59.0+build5-0ubuntu0.16.04.1",
            "firefox-locale-ur": "59.0+build5-0ubuntu0.16.04.1"
        }
    ]
}