USN-930-1: Firefox and Xulrunner vulnerabilities

Ubuntu Security Notice USN-930-1

29th June, 2010

firefox, firefox-3.0, xulrunner-1.9.2 vulnerabilities

A security issue affects these releases of Ubuntu and its derivatives:

  • Ubuntu 10.04 LTS
  • Ubuntu 8.04 LTS

Summary

Firefox could be made to run programs as your login if it opened a specially crafted file or website.

Software description

  • firefox - Safe and easy web browser from Mozilla
  • firefox-3.0 - Safe and easy web browser from Mozilla
  • xulrunner-1.9.2 - XUL + XPCOM application runner

Details

If was discovered that Firefox could be made to access freed memory. If a
user were tricked into viewing a malicious site, a remote attacker could
cause a denial of service or possibly execute arbitrary code with the
privileges of the user invoking the program. This issue only affected
Ubuntu 8.04 LTS. (CVE-2010-1121)

Several flaws were discovered in the browser engine of Firefox. If a
user were tricked into viewing a malicious site, a remote attacker could
cause a denial of service or possibly execute arbitrary code with the
privileges of the user invoking the program. (CVE-2010-1200, CVE-2010-1201,
CVE-2010-1202, CVE-2010-1203)

A flaw was discovered in the way plugin instances interacted. An attacker
could potentially exploit this and use one plugin to access freed memory from a
second plugin to execute arbitrary code with the privileges of the user
invoking the program. (CVE-2010-1198)

An integer overflow was discovered in Firefox. If a user were tricked into
viewing a malicious site, an attacker could overflow a buffer and cause a
denial of service or possibly execute arbitrary code with the privileges of
the user invoking the program. (CVE-2010-1196)

Martin Barbella discovered an integer overflow in an XSLT node sorting
routine. An attacker could exploit this to overflow a buffer and cause a
denial of service or possibly execute arbitrary code with the privileges of
the user invoking the program. (CVE-2010-1199)

Michal Zalewski discovered that the focus behavior of Firefox could be
subverted. If a user were tricked into viewing a malicious site, a remote
attacker could use this to capture keystrokes. (CVE-2010-1125)

Ilja van Sprundel discovered that the 'Content-Disposition: attachment'
HTTP header was ignored when 'Content-Type: multipart' was also present.
Under certain circumstances, this could potentially lead to cross-site
scripting attacks. (CVE-2010-1197)

Amit Klein discovered that Firefox did not seed its random number generator
often enough. An attacker could exploit this to identify and track users
across different web sites. (CVE-2008-5913)

Update instructions

The problem can be corrected by updating your system to the following package version:

Ubuntu 10.04 LTS:
abrowser 3.6.6+nobinonly-0ubuntu0.10.04.1
firefox 3.6.6+nobinonly-0ubuntu0.10.04.1
xulrunner-1.9.2 1.9.2.6+nobinonly-0ubuntu0.10.04.1
Ubuntu 8.04 LTS:
firefox 3.6.6+nobinonly-0ubuntu0.8.04.1
xulrunner-1.9.2 1.9.2.6+nobinonly-0ubuntu0.8.04.1

To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades.

Mozilla has changed the support model for Firefox and they no longer
support version 3.0 of the browser. As a result, Ubuntu is providing an
upgrade to Firefox 3.6 for Ubuntu 8.04 LTS users, which is the most current
stable release of Firefox supported by Mozilla. When upgrading, users
should be aware of the following:

- Firefox 3.6 does not support version 5 of the Sun Java plugin. Please use
icedtea-java7-plugin or sun-java6-plugin instead.
- After upgrading to Firefox 3.6.6, users may be prompted to upgrade 3rd
party Add-Ons. In some cases, an Add-On will not be compatible with
Firefox 3.6.6 and have no update available. In these cases, Firefox will
notify the user that it is disabling the Add-On.
- Upgrades to Ubuntu 8.10 from Ubuntu 8.04 LTS may break the browser.
Ubuntu 8.10 is no longer officially supported and users are required to
upgrade to 9.04 to receive active security support and a functional browser.
- Font configuration cannot be controlled via Gnome settings. This is a
known issue being tracked in https://launchpad.net/bugs/559149 and will
be fixed in a later update.
- helix-player is not currently supported in Firefox 3.6. This is a known
issue and may be fixed in a future update.
- RealAudio via the totem plugin is no longer supported in Firefox 3.6 in
Ubuntu 8.04 LTS. Affected users navigating to Real content will be
prompted to install optional community supported packages.
- In Ubuntu 8.04 LTS the xine plugin is non-functional. After upgrading to
Firefox 3.6, the plugin may cause the browser to crash, while in Firefox
3.0 it would be silently ignored. Users are advised to uninstall
xine-plugin and/or gxineplugin.
- Plugins using external helpers (such as Totem) may not close when using
the Epiphany browser. This is a known issue being tracked in
https://launchpad.net/bugs/599796 and will be fixed in a later update.
This issue only affects Ubuntu 8.04 LTS.

After a standard system upgrade you need to restart Firefox and any
applications that use Xulrunner to effect the necessary changes.

References

CVE-2008-5913, CVE-2010-1121, CVE-2010-1125, CVE-2010-1196, CVE-2010-1197, CVE-2010-1198, CVE-2010-1199, CVE-2010-1200, CVE-2010-1201, CVE-2010-1202, CVE-2010-1203