USN-7078-1: Firefox vulnerability
Published Oct 22, 2024
·Updated
Atte Kettunen discovered that Firefox did not properly validate before inserting ranges into the selection node cache. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code.
Affected Software
2 affected componentsFixes available
All of the following
ubuntu/firefox<131.0.3+build1-0ubuntu0.20.04.1
131.0.3+build1-0ubuntu0.20.04.1
Ubuntu Ubuntu=20.04
Event History
Oct 22, 2024
Advisory Published
via Ubuntu·12:00 AM
Frequently Asked Questions
1
What is the severity of USN-7078-1?
The severity of USN-7078-1 is critical as it can lead to denial of service or arbitrary code execution.
2
How do I fix USN-7078-1?
To fix USN-7078-1, you should update Firefox to version 131.0.3+build1-0ubuntu0.20.04.1 on Ubuntu 20.04.
3
What versions of Firefox are affected by USN-7078-1?
Firefox versions prior to 131.0.3+build1-0ubuntu0.20.04.1 are affected by USN-7078-1.
4
Can USN-7078-1 be exploited remotely?
Yes, USN-7078-1 can potentially be exploited remotely to cause denial of service.
5
What systems are vulnerable to USN-7078-1?
Ubuntu 20.04 systems running affected versions of Firefox are vulnerable to USN-7078-1.