USN-6562-2: Firefox regressions

Published Jan 11, 2024
·
Updated

USN-6562-1 fixed vulnerabilities in Firefox. The update introduced several minor regressions. This update fixes the problem. We apologize for the inconvenience. Original advisory details: Multiple security issues were discovered in Firefox. If a user were tricked into opening a specially crafted website, an attacker could potentially exploit these to cause a denial of service, obtain sensitive information across domains, or execute arbitrary code.(CVE-2023-6865, CVE-2023-6857, CVE-2023-6858, CVE-2023-6859, CVE-2023-6866, CVE-2023-6867, CVE-2023-6861, CVE-2023-6869, CVE-2023-6871, CVE-2023-6872, CVE-2023-6863, CVE-2023-6864, CVE-2023-6873) DoHyun Lee discovered that Firefox did not properly manage memory when used on systems with the Mesa VM driver. An attacker could potentially exploit this issue to execute arbitrary code. (CVE-2023-6856) George Pantela and Hubert Kario discovered that Firefox using multiple NSS NIST curves which were susceptible to a side-channel attack known as "Minerva". An attacker could potentially exploit this issue to obtain sensitive information. (CVE-2023-6135) Andrew Osmond discovered that Firefox did not properly validate the textures produced by remote decoders. An attacker could potentially exploit this issue to escape the sandbox. (CVE-2023-6860)

Affected Software

2 affected componentsFixes available
All of the following
ubuntu/firefox<121.0.1+build1-0ubuntu0.20.04.1
121.0.1+build1-0ubuntu0.20.04.1
Ubuntu Ubuntu=20.04

Event History

Jan 11, 2024
Advisory Published
via Ubuntu·12:00 AM

Frequently Asked Questions

1

What vulnerabilities does USN-6562-2 address?

USN-6562-2 addresses several security issues discovered in Firefox that were introduced in the previous update USN-6562-1.

2

How do I apply the fix for USN-6562-2?

To fix USN-6562-2, update your Firefox package to version 121.0.1+build1-0ubuntu0.20.04.1 on Ubuntu 20.04.

3

What problems were caused by the previous update USN-6562-1?

The previous update USN-6562-1 introduced several minor regressions in Firefox that are corrected by USN-6562-2.

4

Is it safe to use Firefox after applying the update for USN-6562-2?

Yes, after applying the update for USN-6562-2, Firefox should be secure against the previously identified vulnerabilities.

5

What should I do if I encounter issues after updating Firefox due to USN-6562-2?

If you encounter issues after updating due to USN-6562-2, consider reporting the problems to Ubuntu's bug tracking.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203