USN-6992-2: Firefox regressions
USN-6992-1 fixed vulnerabilities in Firefox. The update introduced several minor regressions. This update fixes the problem. We apologize for the inconvenience. Original advisory details: Multiple security issues were discovered in Firefox. If a user were tricked into opening a specially crafted website, an attacker could potentially exploit these to cause a denial of service, obtain sensitive information across domains, or execute arbitrary code. (CVE-2024-8382, CVE-2024-8383, CVE-2024-8386, CVE-2024-8387, CVE-2024-8389) Nils Bars discovered that Firefox contained a type confusion vulnerability when performing certain property name lookups. An attacker could potentially exploit this issue to cause a denial of service, or execute arbitrary code. (CVE-2024-8381) It was discovered that Firefox did not properly manage memory during garbage collection. An attacker could potentially exploit this issue to cause a denial of service, or execute arbitrary code. (CVE-2024-8384) Seunghyun Lee discovered that Firefox contained a type confusion vulnerability when handling certain ArrayTypes. An attacker could potentially exploit this issue to cause a denial of service, or execute arbitrary code. (CVE-2024-8385)
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-6992-2?
USN-6992-2 addresses minor regressions introduced in the previous update for Firefox, while fixing several security vulnerabilities.
How do I fix USN-6992-2?
To fix USN-6992-2, update Firefox to version 130.0.1+build1-0ubuntu0.20.04.1 on Ubuntu 20.04.
What vulnerabilities are addressed in USN-6992-2?
USN-6992-2 resolves multiple security issues discovered in Firefox that could potentially impact user safety.
Is it safe to continue using Firefox without updating USN-6992-2?
Continuing to use the outdated version of Firefox may expose users to security risks addressed by USN-6992-2.
Who should be concerned about USN-6992-2?
Users running Firefox on Ubuntu 20.04 should prioritize updating to address the vulnerabilities fixed in USN-6992-2.