USN-7056-1: Firefox vulnerabilities
Multiple security issues were discovered in Firefox. If a user were tricked into opening a specially crafted website, an attacker could potentially exploit these to cause a denial of service, obtain sensitive information across domains, or execute arbitrary code. (CVE-2024-9392, CVE-2024-9396, CVE-2024-9397, CVE-2024-9398, CVE-2024-9399, CVE-2024-9400, CVE-2024-9401, CVE-2024-9402, CVE-2024-9403) Masato Kinugawa discovered that Firefox did not properly validate javascript under the "resource://pdf.js" origin. An attacker could potentially exploit this issue to execute arbitrary javascript code and access cross-origin PDF content. (CVE-2024-9393) Masato Kinugawa discovered that Firefox did not properly validate javascript under the "resource://devtools" origin. An attacker could potentially exploit this issue to execute arbitrary javascript code and access cross-origin JSON content. (CVE-2024-9394)
Affected Software
Event History
Child vulnerabilities
Contains the following vulnerabilities.
Frequently Asked Questions
What is the severity of USN-7056-1?
USN-7056-1 addresses multiple critical security vulnerabilities in Firefox that could lead to denial of service, sensitive information exposure, or arbitrary code execution.
How do I fix USN-7056-1?
To mitigate the vulnerabilities outlined in USN-7056-1, update Firefox to version 131.0+build1.1-0ubuntu0.20.04.1 or later.
What versions of Ubuntu are affected by USN-7056-1?
USN-7056-1 affects Ubuntu 20.04 running the Firefox package.
What could happen if I do not address USN-7056-1?
Failing to address USN-7056-1 may leave your system vulnerable to exploits that could compromise sensitive data or disrupt operations.
Is there a workaround for the vulnerabilities in USN-7056-1?
Currently, the best approach to mitigate the issues in USN-7056-1 is to promptly update to the latest version of Firefox.