USN-3111-1: Firefox vulnerabilities
27 October 2016
Several security issues were fixed in Firefox.
Releases
Packages
- firefox - Mozilla Open Source web browser
Details
A use-after-free was discovered in service workers. If a user were tricked
in to opening a specially crafted website, an attacker could potentially
exploit this to cause a denial of service via program crash, or execute
arbitrary code. (CVE-2016-5287)
It was discovered that web content could access information in the HTTP
cache in some circumstances. An attacker could potentially exploit this
to obtain sensitive information. (CVE-2016-5288)
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 16.10
Ubuntu 16.04
Ubuntu 14.04
Ubuntu 12.04
After a standard system update you need to restart Firefox to make
all the necessary changes.