USN-6703-1

See a problem?
Source
https://ubuntu.com/security/notices/USN-6703-1
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/USN-6703-1.json
JSON Data
https://api.osv.dev/v1/vulns/USN-6703-1
Related
  • CVE-2023-5388
  • CVE-2024-2606
  • CVE-2024-2607
  • CVE-2024-2608
  • CVE-2024-2609
  • CVE-2024-2610
  • CVE-2024-2611
  • CVE-2024-2612
  • CVE-2024-2613
  • CVE-2024-2614
  • CVE-2024-2615
Published
2024-03-20T05:48:06.785617Z
Modified
2024-03-20T05:48:06.785617Z
Summary
firefox vulnerabilities
Details

Multiple security issues were discovered in Firefox. If a user were tricked into opening a specially crafted website, an attacker could potentially exploit these to cause a denial of service, obtain sensitive information across domains, or execute arbitrary code. (CVE-2024-2609, CVE-2024-2611, CVE-2024-2614, CVE-2024-2615)

Hubert Kario discovered that Firefox had a timing side-channel when performing RSA decryption. A remote attacker could possibly use this issue to recover sensitive information. (CVE-2023-5388)

It was discovered that Firefox did not properly handle WASM register values in some circumstances. An attacker could potentially exploit this issue to cause a denial of service. (CVE-2024-2606)

Gary Kwong discovered that Firefox incorrectly updated return registers for JIT code on Armv7-A systems. An attacker could potentially exploit this issue to execute arbitrary code. (CVE-2024-2607)

Ronald Crane discovered that Firefox did not properly manage memory during character encoding. An attacker could potentially exploit this issue to cause a denial of service. (CVE-2024-2608)

Georg Felber and Marco Squarcina discovered that Firefox incorrectly handled html and body tags. An attacker who was able to inject markup into a page otherwise protected by a Content Security Policy may have been able obtain sensitive information. (CVE-2024-2610)

Ronald Crane discovered a use-after-free in Firefox when handling code in SafeRefPtr. An attacker could potentially exploit this issue to cause a denial of service, or execute arbitrary code. (CVE-2024-2612)

Max Inden discovered that Firefox incorrectly handled QUIC ACK frame decoding. A attacker could potentially exploit this issue to cause a denial of service. (CVE-2024-2613)

References

Affected packages

Ubuntu:20.04:LTS / firefox

Package

Name
firefox

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
124.0+build1-0ubuntu0.20.04.1

Ecosystem specific

{
    "availability": "No subscription needed",
    "binaries": [
        {
            "firefox-locale-de": "124.0+build1-0ubuntu0.20.04.1",
            "firefox-locale-nl": "124.0+build1-0ubuntu0.20.04.1",
            "firefox-locale-kn": "124.0+build1-0ubuntu0.20.04.1",
            "firefox-locale-gl": "124.0+build1-0ubuntu0.20.04.1",
            "firefox-locale-fy": "124.0+build1-0ubuntu0.20.04.1",
            "firefox-locale-eo": "124.0+build1-0ubuntu0.20.04.1",
            "firefox-locale-km": "124.0+build1-0ubuntu0.20.04.1",
            "firefox-locale-or": "124.0+build1-0ubuntu0.20.04.1",
            "firefox-locale-az": "124.0+build1-0ubuntu0.20.04.1",
            "firefox-locale-lt": "124.0+build1-0ubuntu0.20.04.1",
            "firefox-locale-hy": "124.0+build1-0ubuntu0.20.04.1",
            "firefox-locale-kk": "124.0+build1-0ubuntu0.20.04.1",
            "firefox-locale-sv": "124.0+build1-0ubuntu0.20.04.1",
            "firefox-locale-uk": "124.0+build1-0ubuntu0.20.04.1",
            "firefox-locale-sr": "124.0+build1-0ubuntu0.20.04.1",
            "firefox-locale-ca": "124.0+build1-0ubuntu0.20.04.1",
            "firefox-locale-is": "124.0+build1-0ubuntu0.20.04.1",
            "firefox-locale-ne": "124.0+build1-0ubuntu0.20.04.1",
            "firefox-locale-ga": "124.0+build1-0ubuntu0.20.04.1",
            "firefox-locale-it": "124.0+build1-0ubuntu0.20.04.1",
            "firefox-locale-ja": "124.0+build1-0ubuntu0.20.04.1",
            "firefox-locale-lg": "124.0+build1-0ubuntu0.20.04.1",
            "firefox-locale-ms": "124.0+build1-0ubuntu0.20.04.1",
            "firefox-dev": "124.0+build1-0ubuntu0.20.04.1",
            "firefox-locale-ia": "124.0+build1-0ubuntu0.20.04.1",
            "firefox-locale-ko": "124.0+build1-0ubuntu0.20.04.1",
            "firefox-locale-hr": "124.0+build1-0ubuntu0.20.04.1",
            "firefox-locale-mai": "124.0+build1-0ubuntu0.20.04.1",
            "firefox-locale-nb": "124.0+build1-0ubuntu0.20.04.1",
            "firefox-mozsymbols": "124.0+build1-0ubuntu0.20.04.1",
            "firefox-locale-vi": "124.0+build1-0ubuntu0.20.04.1",
            "firefox-locale-zh-hans": "124.0+build1-0ubuntu0.20.04.1",
            "firefox-locale-he": "124.0+build1-0ubuntu0.20.04.1",
            "firefox-locale-sw": "124.0+build1-0ubuntu0.20.04.1",
            "firefox-locale-el": "124.0+build1-0ubuntu0.20.04.1",
            "firefox-locale-oc": "124.0+build1-0ubuntu0.20.04.1",
            "firefox-locale-xh": "124.0+build1-0ubuntu0.20.04.1",
            "firefox-locale-tg": "124.0+build1-0ubuntu0.20.04.1",
            "firefox-locale-nn": "124.0+build1-0ubuntu0.20.04.1",
            "firefox-locale-csb": "124.0+build1-0ubuntu0.20.04.1",
            "firefox-locale-ar": "124.0+build1-0ubuntu0.20.04.1",
            "firefox-locale-cs": "124.0+build1-0ubuntu0.20.04.1",
            "firefox-locale-gn": "124.0+build1-0ubuntu0.20.04.1",
            "firefox-locale-hsb": "124.0+build1-0ubuntu0.20.04.1",
            "firefox-locale-zu": "124.0+build1-0ubuntu0.20.04.1",
            "firefox-locale-my": "124.0+build1-0ubuntu0.20.04.1",
            "firefox-locale-ro": "124.0+build1-0ubuntu0.20.04.1",
            "firefox-geckodriver": "124.0+build1-0ubuntu0.20.04.1",
            "firefox-locale-szl": "124.0+build1-0ubuntu0.20.04.1",
            "firefox-locale-af": "124.0+build1-0ubuntu0.20.04.1",
            "firefox-locale-sk": "124.0+build1-0ubuntu0.20.04.1",
            "firefox-locale-nso": "124.0+build1-0ubuntu0.20.04.1",
            "firefox-locale-si": "124.0+build1-0ubuntu0.20.04.1",
            "firefox": "124.0+build1-0ubuntu0.20.04.1",
            "firefox-locale-cy": "124.0+build1-0ubuntu0.20.04.1",
            "firefox-locale-fa": "124.0+build1-0ubuntu0.20.04.1",
            "firefox-locale-cak": "124.0+build1-0ubuntu0.20.04.1",
            "firefox-locale-sq": "124.0+build1-0ubuntu0.20.04.1",
            "firefox-locale-en": "124.0+build1-0ubuntu0.20.04.1",
            "firefox-locale-tr": "124.0+build1-0ubuntu0.20.04.1",
            "firefox-locale-br": "124.0+build1-0ubuntu0.20.04.1",
            "firefox-locale-et": "124.0+build1-0ubuntu0.20.04.1",
            "firefox-locale-ast": "124.0+build1-0ubuntu0.20.04.1",
            "firefox-locale-th": "124.0+build1-0ubuntu0.20.04.1",
            "firefox-locale-da": "124.0+build1-0ubuntu0.20.04.1",
            "firefox-locale-fi": "124.0+build1-0ubuntu0.20.04.1",
            "firefox-locale-ku": "124.0+build1-0ubuntu0.20.04.1",
            "firefox-locale-mn": "124.0+build1-0ubuntu0.20.04.1",
            "firefox-locale-ru": "124.0+build1-0ubuntu0.20.04.1",
            "firefox-locale-mk": "124.0+build1-0ubuntu0.20.04.1",
            "firefox-locale-bg": "124.0+build1-0ubuntu0.20.04.1",
            "firefox-locale-hu": "124.0+build1-0ubuntu0.20.04.1",
            "firefox-locale-gu": "124.0+build1-0ubuntu0.20.04.1",
            "firefox-locale-bn": "124.0+build1-0ubuntu0.20.04.1",
            "firefox-locale-kab": "124.0+build1-0ubuntu0.20.04.1",
            "firefox-locale-ml": "124.0+build1-0ubuntu0.20.04.1",
            "firefox-locale-an": "124.0+build1-0ubuntu0.20.04.1",
            "firefox-locale-be": "124.0+build1-0ubuntu0.20.04.1",
            "firefox-locale-eu": "124.0+build1-0ubuntu0.20.04.1",
            "firefox-locale-fr": "124.0+build1-0ubuntu0.20.04.1",
            "firefox-locale-pa": "124.0+build1-0ubuntu0.20.04.1",
            "firefox-locale-as": "124.0+build1-0ubuntu0.20.04.1",
            "firefox-locale-id": "124.0+build1-0ubuntu0.20.04.1",
            "firefox-locale-mr": "124.0+build1-0ubuntu0.20.04.1",
            "firefox-locale-bs": "124.0+build1-0ubuntu0.20.04.1",
            "firefox-locale-te": "124.0+build1-0ubuntu0.20.04.1",
            "firefox-locale-lv": "124.0+build1-0ubuntu0.20.04.1",
            "firefox-locale-ka": "124.0+build1-0ubuntu0.20.04.1",
            "firefox-locale-ta": "124.0+build1-0ubuntu0.20.04.1",
            "firefox-locale-gd": "124.0+build1-0ubuntu0.20.04.1",
            "firefox-locale-zh-hant": "124.0+build1-0ubuntu0.20.04.1",
            "firefox-locale-uz": "124.0+build1-0ubuntu0.20.04.1",
            "firefox-locale-hi": "124.0+build1-0ubuntu0.20.04.1",
            "firefox-locale-es": "124.0+build1-0ubuntu0.20.04.1",
            "firefox-locale-ur": "124.0+build1-0ubuntu0.20.04.1",
            "firefox-locale-pl": "124.0+build1-0ubuntu0.20.04.1",
            "firefox-locale-pt": "124.0+build1-0ubuntu0.20.04.1",
            "firefox-locale-sl": "124.0+build1-0ubuntu0.20.04.1"
        }
    ]
}