USN-3918-1

See a problem?
Source
https://ubuntu.com/security/notices/USN-3918-1
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/USN-3918-1.json
JSON Data
https://api.osv.dev/v1/vulns/USN-3918-1
Related
  • CVE-2019-9788
  • CVE-2019-9789
  • CVE-2019-9790
  • CVE-2019-9791
  • CVE-2019-9792
  • CVE-2019-9793
  • CVE-2019-9795
  • CVE-2019-9796
  • CVE-2019-9797
  • CVE-2019-9799
  • CVE-2019-9802
  • CVE-2019-9803
  • CVE-2019-9805
  • CVE-2019-9806
  • CVE-2019-9807
  • CVE-2019-9808
  • CVE-2019-9809
Published
2019-03-21T20:55:03.840020Z
Modified
2019-03-21T20:55:03.840020Z
Summary
firefox vulnerabilities
Details

Multiple security issues were discovered in Firefox. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit these to cause a denial of service via application crash, denial of service via successive FTP authorization prompts or modal alerts, trick the user with confusing permission request prompts, obtain sensitive information, conduct social engineering attacks, or execute arbitrary code. (CVE-2019-9788, CVE-2019-9789, CVE-2019-9790, CVE-2019-9791, CVE-2019-9792, CVE-2019-9795, CVE-2019-9796, CVE-2019-9797, CVE-2019-9799, CVE-2019-9802, CVE-2019-9805, CVE-2019-9806, CVE-2019-9807, CVE-2019-9808, CVE-2019-9809)

A mechanism was discovered that removes some bounds checking for string, array, or typed array accesses if Spectre mitigations have been disabled. If a user were tricked in to opening a specially crafted website with Spectre mitigations disabled, an attacker could potentially exploit this to cause a denial of service, or execute arbitrary code. (CVE-2019-9793)

It was discovered that Upgrade-Insecure-Requests was incorrectly enforced for same-origin navigation. An attacker could potentially exploit this to conduct machine-in-the-middle (MITM) attacks. (CVE-2019-9803)

References

Affected packages

Ubuntu:18.04:LTS / firefox

Package

Name
firefox

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
66.0+build3-0ubuntu0.18.04.1

Ecosystem specific

{
    "availability": "No subscription needed",
    "binaries": [
        {
            "firefox-locale-sl": "66.0+build3-0ubuntu0.18.04.1",
            "firefox-locale-nl": "66.0+build3-0ubuntu0.18.04.1",
            "firefox-locale-kn": "66.0+build3-0ubuntu0.18.04.1",
            "firefox-locale-gl": "66.0+build3-0ubuntu0.18.04.1",
            "firefox-locale-fy": "66.0+build3-0ubuntu0.18.04.1",
            "firefox-locale-kk": "66.0+build3-0ubuntu0.18.04.1",
            "firefox-locale-km": "66.0+build3-0ubuntu0.18.04.1",
            "firefox-locale-or": "66.0+build3-0ubuntu0.18.04.1",
            "firefox-locale-az": "66.0+build3-0ubuntu0.18.04.1",
            "firefox-locale-lt": "66.0+build3-0ubuntu0.18.04.1",
            "firefox-locale-hy": "66.0+build3-0ubuntu0.18.04.1",
            "firefox-locale-eo": "66.0+build3-0ubuntu0.18.04.1",
            "firefox-locale-sv": "66.0+build3-0ubuntu0.18.04.1",
            "firefox-testsuite": "66.0+build3-0ubuntu0.18.04.1",
            "firefox-locale-sr": "66.0+build3-0ubuntu0.18.04.1",
            "firefox-locale-is": "66.0+build3-0ubuntu0.18.04.1",
            "firefox-locale-ca": "66.0+build3-0ubuntu0.18.04.1",
            "firefox-locale-uk": "66.0+build3-0ubuntu0.18.04.1",
            "firefox-locale-ne": "66.0+build3-0ubuntu0.18.04.1",
            "firefox-locale-ga": "66.0+build3-0ubuntu0.18.04.1",
            "firefox-locale-it": "66.0+build3-0ubuntu0.18.04.1",
            "firefox-locale-ja": "66.0+build3-0ubuntu0.18.04.1",
            "firefox-locale-lg": "66.0+build3-0ubuntu0.18.04.1",
            "firefox-locale-ms": "66.0+build3-0ubuntu0.18.04.1",
            "firefox-locale-zh-hans": "66.0+build3-0ubuntu0.18.04.1",
            "firefox-locale-ia": "66.0+build3-0ubuntu0.18.04.1",
            "firefox-locale-ko": "66.0+build3-0ubuntu0.18.04.1",
            "firefox-locale-hr": "66.0+build3-0ubuntu0.18.04.1",
            "firefox-locale-mai": "66.0+build3-0ubuntu0.18.04.1",
            "firefox-locale-nb": "66.0+build3-0ubuntu0.18.04.1",
            "firefox-mozsymbols": "66.0+build3-0ubuntu0.18.04.1",
            "firefox-locale-vi": "66.0+build3-0ubuntu0.18.04.1",
            "firefox-dev": "66.0+build3-0ubuntu0.18.04.1",
            "firefox-locale-he": "66.0+build3-0ubuntu0.18.04.1",
            "firefox-locale-sw": "66.0+build3-0ubuntu0.18.04.1",
            "firefox-locale-el": "66.0+build3-0ubuntu0.18.04.1",
            "firefox-locale-oc": "66.0+build3-0ubuntu0.18.04.1",
            "firefox-locale-xh": "66.0+build3-0ubuntu0.18.04.1",
            "firefox-locale-nn": "66.0+build3-0ubuntu0.18.04.1",
            "firefox-locale-ar": "66.0+build3-0ubuntu0.18.04.1",
            "firefox-locale-csb": "66.0+build3-0ubuntu0.18.04.1",
            "firefox-locale-cs": "66.0+build3-0ubuntu0.18.04.1",
            "firefox-locale-gn": "66.0+build3-0ubuntu0.18.04.1",
            "firefox-locale-hsb": "66.0+build3-0ubuntu0.18.04.1",
            "firefox-locale-zu": "66.0+build3-0ubuntu0.18.04.1",
            "firefox-locale-my": "66.0+build3-0ubuntu0.18.04.1",
            "firefox-locale-ro": "66.0+build3-0ubuntu0.18.04.1",
            "firefox-globalmenu": "66.0+build3-0ubuntu0.18.04.1",
            "firefox-locale-nso": "66.0+build3-0ubuntu0.18.04.1",
            "firefox-locale-af": "66.0+build3-0ubuntu0.18.04.1",
            "firefox-locale-sk": "66.0+build3-0ubuntu0.18.04.1",
            "firefox-locale-si": "66.0+build3-0ubuntu0.18.04.1",
            "firefox": "66.0+build3-0ubuntu0.18.04.1",
            "firefox-locale-cy": "66.0+build3-0ubuntu0.18.04.1",
            "firefox-locale-fa": "66.0+build3-0ubuntu0.18.04.1",
            "firefox-locale-cak": "66.0+build3-0ubuntu0.18.04.1",
            "firefox-locale-sq": "66.0+build3-0ubuntu0.18.04.1",
            "firefox-locale-en": "66.0+build3-0ubuntu0.18.04.1",
            "firefox-locale-tr": "66.0+build3-0ubuntu0.18.04.1",
            "firefox-locale-br": "66.0+build3-0ubuntu0.18.04.1",
            "firefox-locale-et": "66.0+build3-0ubuntu0.18.04.1",
            "firefox-locale-ast": "66.0+build3-0ubuntu0.18.04.1",
            "firefox-locale-th": "66.0+build3-0ubuntu0.18.04.1",
            "firefox-locale-da": "66.0+build3-0ubuntu0.18.04.1",
            "firefox-locale-fi": "66.0+build3-0ubuntu0.18.04.1",
            "firefox-locale-ku": "66.0+build3-0ubuntu0.18.04.1",
            "firefox-locale-mn": "66.0+build3-0ubuntu0.18.04.1",
            "firefox-locale-ru": "66.0+build3-0ubuntu0.18.04.1",
            "firefox-locale-mk": "66.0+build3-0ubuntu0.18.04.1",
            "firefox-locale-bg": "66.0+build3-0ubuntu0.18.04.1",
            "firefox-locale-hu": "66.0+build3-0ubuntu0.18.04.1",
            "firefox-locale-gu": "66.0+build3-0ubuntu0.18.04.1",
            "firefox-locale-bn": "66.0+build3-0ubuntu0.18.04.1",
            "firefox-locale-kab": "66.0+build3-0ubuntu0.18.04.1",
            "firefox-locale-ml": "66.0+build3-0ubuntu0.18.04.1",
            "firefox-locale-an": "66.0+build3-0ubuntu0.18.04.1",
            "firefox-locale-be": "66.0+build3-0ubuntu0.18.04.1",
            "firefox-locale-eu": "66.0+build3-0ubuntu0.18.04.1",
            "firefox-locale-fr": "66.0+build3-0ubuntu0.18.04.1",
            "firefox-locale-pa": "66.0+build3-0ubuntu0.18.04.1",
            "firefox-locale-as": "66.0+build3-0ubuntu0.18.04.1",
            "firefox-locale-ta": "66.0+build3-0ubuntu0.18.04.1",
            "firefox-locale-pl": "66.0+build3-0ubuntu0.18.04.1",
            "firefox-locale-bs": "66.0+build3-0ubuntu0.18.04.1",
            "firefox-locale-te": "66.0+build3-0ubuntu0.18.04.1",
            "firefox-locale-id": "66.0+build3-0ubuntu0.18.04.1",
            "firefox-locale-ka": "66.0+build3-0ubuntu0.18.04.1",
            "firefox-locale-lv": "66.0+build3-0ubuntu0.18.04.1",
            "firefox-locale-gd": "66.0+build3-0ubuntu0.18.04.1",
            "firefox-locale-uz": "66.0+build3-0ubuntu0.18.04.1",
            "firefox-locale-zh-hant": "66.0+build3-0ubuntu0.18.04.1",
            "firefox-locale-hi": "66.0+build3-0ubuntu0.18.04.1",
            "firefox-locale-es": "66.0+build3-0ubuntu0.18.04.1",
            "firefox-locale-de": "66.0+build3-0ubuntu0.18.04.1",
            "firefox-locale-mr": "66.0+build3-0ubuntu0.18.04.1",
            "firefox-locale-pt": "66.0+build3-0ubuntu0.18.04.1",
            "firefox-locale-ur": "66.0+build3-0ubuntu0.18.04.1"
        }
    ]
}

Ubuntu:16.04:LTS / firefox

Package

Name
firefox

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
66.0+build3-0ubuntu0.16.04.2

Ecosystem specific

{
    "availability": "No subscription needed",
    "binaries": [
        {
            "firefox-locale-sl": "66.0+build3-0ubuntu0.16.04.2",
            "firefox-locale-nl": "66.0+build3-0ubuntu0.16.04.2",
            "firefox-locale-kn": "66.0+build3-0ubuntu0.16.04.2",
            "firefox-locale-gl": "66.0+build3-0ubuntu0.16.04.2",
            "firefox-locale-fy": "66.0+build3-0ubuntu0.16.04.2",
            "firefox-locale-kk": "66.0+build3-0ubuntu0.16.04.2",
            "firefox-locale-km": "66.0+build3-0ubuntu0.16.04.2",
            "firefox-locale-or": "66.0+build3-0ubuntu0.16.04.2",
            "firefox-locale-az": "66.0+build3-0ubuntu0.16.04.2",
            "firefox-locale-lt": "66.0+build3-0ubuntu0.16.04.2",
            "firefox-locale-hy": "66.0+build3-0ubuntu0.16.04.2",
            "firefox-locale-eo": "66.0+build3-0ubuntu0.16.04.2",
            "firefox-locale-sv": "66.0+build3-0ubuntu0.16.04.2",
            "firefox-testsuite": "66.0+build3-0ubuntu0.16.04.2",
            "firefox-locale-sr": "66.0+build3-0ubuntu0.16.04.2",
            "firefox-locale-is": "66.0+build3-0ubuntu0.16.04.2",
            "firefox-locale-ca": "66.0+build3-0ubuntu0.16.04.2",
            "firefox-locale-uk": "66.0+build3-0ubuntu0.16.04.2",
            "firefox-locale-ne": "66.0+build3-0ubuntu0.16.04.2",
            "firefox-locale-ga": "66.0+build3-0ubuntu0.16.04.2",
            "firefox-locale-it": "66.0+build3-0ubuntu0.16.04.2",
            "firefox-locale-ja": "66.0+build3-0ubuntu0.16.04.2",
            "firefox-locale-lg": "66.0+build3-0ubuntu0.16.04.2",
            "firefox-locale-ms": "66.0+build3-0ubuntu0.16.04.2",
            "firefox-locale-zh-hans": "66.0+build3-0ubuntu0.16.04.2",
            "firefox-locale-ia": "66.0+build3-0ubuntu0.16.04.2",
            "firefox-locale-ko": "66.0+build3-0ubuntu0.16.04.2",
            "firefox-locale-hr": "66.0+build3-0ubuntu0.16.04.2",
            "firefox-locale-mai": "66.0+build3-0ubuntu0.16.04.2",
            "firefox-locale-nb": "66.0+build3-0ubuntu0.16.04.2",
            "firefox-mozsymbols": "66.0+build3-0ubuntu0.16.04.2",
            "firefox-locale-vi": "66.0+build3-0ubuntu0.16.04.2",
            "firefox-dev": "66.0+build3-0ubuntu0.16.04.2",
            "firefox-locale-he": "66.0+build3-0ubuntu0.16.04.2",
            "firefox-locale-sw": "66.0+build3-0ubuntu0.16.04.2",
            "firefox-locale-el": "66.0+build3-0ubuntu0.16.04.2",
            "firefox-locale-oc": "66.0+build3-0ubuntu0.16.04.2",
            "firefox-locale-xh": "66.0+build3-0ubuntu0.16.04.2",
            "firefox-locale-nn": "66.0+build3-0ubuntu0.16.04.2",
            "firefox-locale-ar": "66.0+build3-0ubuntu0.16.04.2",
            "firefox-locale-csb": "66.0+build3-0ubuntu0.16.04.2",
            "firefox-locale-cs": "66.0+build3-0ubuntu0.16.04.2",
            "firefox-locale-gn": "66.0+build3-0ubuntu0.16.04.2",
            "firefox-locale-hsb": "66.0+build3-0ubuntu0.16.04.2",
            "firefox-locale-zu": "66.0+build3-0ubuntu0.16.04.2",
            "firefox-locale-my": "66.0+build3-0ubuntu0.16.04.2",
            "firefox-locale-ro": "66.0+build3-0ubuntu0.16.04.2",
            "firefox-globalmenu": "66.0+build3-0ubuntu0.16.04.2",
            "firefox-locale-nso": "66.0+build3-0ubuntu0.16.04.2",
            "firefox-locale-af": "66.0+build3-0ubuntu0.16.04.2",
            "firefox-locale-sk": "66.0+build3-0ubuntu0.16.04.2",
            "firefox-locale-si": "66.0+build3-0ubuntu0.16.04.2",
            "firefox": "66.0+build3-0ubuntu0.16.04.2",
            "firefox-locale-cy": "66.0+build3-0ubuntu0.16.04.2",
            "firefox-locale-fa": "66.0+build3-0ubuntu0.16.04.2",
            "firefox-locale-cak": "66.0+build3-0ubuntu0.16.04.2",
            "firefox-locale-sq": "66.0+build3-0ubuntu0.16.04.2",
            "firefox-locale-en": "66.0+build3-0ubuntu0.16.04.2",
            "firefox-locale-tr": "66.0+build3-0ubuntu0.16.04.2",
            "firefox-locale-br": "66.0+build3-0ubuntu0.16.04.2",
            "firefox-locale-et": "66.0+build3-0ubuntu0.16.04.2",
            "firefox-locale-ast": "66.0+build3-0ubuntu0.16.04.2",
            "firefox-locale-th": "66.0+build3-0ubuntu0.16.04.2",
            "firefox-locale-da": "66.0+build3-0ubuntu0.16.04.2",
            "firefox-locale-fi": "66.0+build3-0ubuntu0.16.04.2",
            "firefox-locale-ku": "66.0+build3-0ubuntu0.16.04.2",
            "firefox-locale-mn": "66.0+build3-0ubuntu0.16.04.2",
            "firefox-locale-ru": "66.0+build3-0ubuntu0.16.04.2",
            "firefox-locale-mk": "66.0+build3-0ubuntu0.16.04.2",
            "firefox-locale-bg": "66.0+build3-0ubuntu0.16.04.2",
            "firefox-locale-hu": "66.0+build3-0ubuntu0.16.04.2",
            "firefox-locale-gu": "66.0+build3-0ubuntu0.16.04.2",
            "firefox-locale-bn": "66.0+build3-0ubuntu0.16.04.2",
            "firefox-locale-kab": "66.0+build3-0ubuntu0.16.04.2",
            "firefox-locale-ml": "66.0+build3-0ubuntu0.16.04.2",
            "firefox-locale-an": "66.0+build3-0ubuntu0.16.04.2",
            "firefox-locale-be": "66.0+build3-0ubuntu0.16.04.2",
            "firefox-locale-eu": "66.0+build3-0ubuntu0.16.04.2",
            "firefox-locale-fr": "66.0+build3-0ubuntu0.16.04.2",
            "firefox-locale-pa": "66.0+build3-0ubuntu0.16.04.2",
            "firefox-locale-as": "66.0+build3-0ubuntu0.16.04.2",
            "firefox-locale-ta": "66.0+build3-0ubuntu0.16.04.2",
            "firefox-locale-pl": "66.0+build3-0ubuntu0.16.04.2",
            "firefox-locale-bs": "66.0+build3-0ubuntu0.16.04.2",
            "firefox-locale-te": "66.0+build3-0ubuntu0.16.04.2",
            "firefox-locale-id": "66.0+build3-0ubuntu0.16.04.2",
            "firefox-locale-ka": "66.0+build3-0ubuntu0.16.04.2",
            "firefox-locale-lv": "66.0+build3-0ubuntu0.16.04.2",
            "firefox-locale-gd": "66.0+build3-0ubuntu0.16.04.2",
            "firefox-locale-uz": "66.0+build3-0ubuntu0.16.04.2",
            "firefox-locale-zh-hant": "66.0+build3-0ubuntu0.16.04.2",
            "firefox-locale-hi": "66.0+build3-0ubuntu0.16.04.2",
            "firefox-locale-es": "66.0+build3-0ubuntu0.16.04.2",
            "firefox-locale-de": "66.0+build3-0ubuntu0.16.04.2",
            "firefox-locale-mr": "66.0+build3-0ubuntu0.16.04.2",
            "firefox-locale-pt": "66.0+build3-0ubuntu0.16.04.2",
            "firefox-locale-ur": "66.0+build3-0ubuntu0.16.04.2"
        }
    ]
}