USN-7065-1: Firefox vulnerability
Published Oct 14, 2024
·Updated
Damien Schaeffer discovered that Firefox did not properly manage memory in the content process when handling Animation timelines, leading to a use after free vulnerability. An attacker could possibly use this issue to achieve remote code execution.
Affected Software
2 affected componentsFixes available
All of the following
ubuntu/firefox<131.0.2+build1-0ubuntu0.20.04.1
131.0.2+build1-0ubuntu0.20.04.1
Ubuntu Ubuntu=20.04
Event History
Oct 14, 2024
Advisory Published
via Ubuntu·12:00 AM
Frequently Asked Questions
1
What is the severity of USN-7065-1?
USN-7065-1 is considered a high severity vulnerability due to its potential for remote code execution.
2
How do I fix USN-7065-1?
To fix USN-7065-1, update Firefox to version 131.0.2+build1-0ubuntu0.20.04.1 on Ubuntu 20.04.
3
What does USN-7065-1 affect?
USN-7065-1 affects the Firefox package on Ubuntu 20.04.
4
What type of vulnerability is described in USN-7065-1?
USN-7065-1 describes a use after free vulnerability related to memory management in Firefox.
5
Who discovered the vulnerability in USN-7065-1?
The vulnerability in USN-7065-1 was discovered by Damien Schaeffer.