USN-4408-1: Firefox vulnerabilities
Multiple security issues were discovered in Firefox. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit these to cause a denial of service, obtain sensitive information, bypass permission prompts, or execute arbitrary code. (CVE-2020-12415, CVE-2020-12416, CVE-2020-12417, CVE-2020-12418, CVE-2020-12419, CVE-2020-12420, CVE-2020-12422, CVE-2020-12424, CVE-2020-12425, CVE-2020-12426) It was discovered that when performing add-on updates, certificate chains not terminating with built-in roots were silently rejected. This could result in add-ons becoming outdated. (CVE-2020-12421)
Affected Software
Event History
Child vulnerabilities
Contains the following vulnerabilities.
Frequently Asked Questions
What is the severity of USN-4408-1?
The severity of USN-4408-1 is high.
How can an attacker exploit USN-4408-1?
An attacker can exploit USN-4408-1 by tricking a user into opening a specially crafted website.
What are the potential impacts of USN-4408-1?
The potential impacts of USN-4408-1 include denial of service, obtaining sensitive information, bypassing permission prompts, or executing arbitrary code.
Which versions of Firefox are affected by USN-4408-1?
Versions 78.0.1+build1-0ubuntu0.20.04.1, 78.0.1+build1-0ubuntu0.19.10.1, 78.0.1+build1-0ubuntu0.18.04.1, and 78.0.1+build1-0ubuntu0.16.04.1 of Firefox are affected by USN-4408-1.
How do I fix USN-4408-1?
To fix USN-4408-1, update Firefox to version 78.0.1+build1-0ubuntu0.20.04.1 (for Ubuntu 20.04), 78.0.1+build1-0ubuntu0.19.10.1 (for Ubuntu 19.10), 78.0.1+build1-0ubuntu0.18.04.1 (for Ubuntu 18.04), or 78.0.1+build1-0ubuntu0.16.04.1 (for Ubuntu 16.04).