ESB-2018.1460.2 - UPDATE [Ubuntu] Firefox: Multiple vulnerabilities 2018-05-21

Printable version
PGP/GPG verifiable version

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

===========================================================================
             AUSCERT External Security Bulletin Redistribution

                              ESB-2018.1460.2
                          Firefox vulnerabilities
                                21 May 2018

===========================================================================

        AusCERT Security Bulletin Summary
        ---------------------------------

Product:           Firefox
Publisher:         Ubuntu
Operating System:  Ubuntu
Impact/Access:     Execute Arbitrary Code/Commands -- Remote with User Interaction
                   Cross-site Scripting            -- Remote with User Interaction
                   Denial of Service               -- Remote with User Interaction
                   Provide Misleading Information  -- Remote with User Interaction
                   Access Confidential Data        -- Remote with User Interaction
                   Reduced Security                -- Remote with User Interaction
Resolution:        Patch/Upgrade
CVE Names:         CVE-2018-5182 CVE-2018-5181 CVE-2018-5180
                   CVE-2018-5177 CVE-2018-5176 CVE-2018-5175
                   CVE-2018-5173 CVE-2018-5172 CVE-2018-5169
                   CVE-2018-5168 CVE-2018-5167 CVE-2018-5166
                   CVE-2018-5164 CVE-2018-5163 CVE-2018-5160
                   CVE-2018-5159 CVE-2018-5158 CVE-2018-5157
                   CVE-2018-5155 CVE-2018-5154 CVE-2018-5153
                   CVE-2018-5152 CVE-2018-5151 CVE-2018-5150

Reference:         ASB-2018.0110
                   ASB-2018.0109

Original Bulletin: 
   http://www.ubuntu.com/usn/usn-3645-1
   http://www.ubuntu.com/usn/usn-3645-2

Comment: This bulletin contains two (2) Ubuntu security advisories.

Revision History:  May 21 2018: Regression patched: long UI pauses
                   May 14 2018: Initial Release

- --------------------------BEGIN INCLUDED TEXT--------------------

==========================================================================
Ubuntu Security Notice USN-3645-1
May 11, 2018

firefox vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- - Ubuntu 18.04 LTS
- - Ubuntu 17.10
- - Ubuntu 16.04 LTS
- - Ubuntu 14.04 LTS

Summary:

Firefox could be made to crash or run programs as your login if it
opened a malicious website.

Software Description:
- - firefox: Mozilla Open Source web browser

Details:

Multiple security issues were discovered in Firefox. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service via application
crash, bypass same-origin restrictions, conduct cross-site scripting (XSS)
attacks, install lightweight themes without user interaction, spoof the
filename in the downloads panel, or execute arbitrary code.
(CVE-2018-5150, CVE-2018-5151, CVE-2018-5153, CVE-2018-5154,
CVE-2018-5155, CVE-2018-5157, CVE-2018-5158, CVE-2018-5159, CVE-2018-5160,
CVE-2018-5163, CVE-2018-5164, CVE-2018-5168, CVE-2018-5173, CVE-2018-5175,
CVE-2018-5177, CVE-2018-5180)

Multiple security issues were discovered with WebExtensions. If a user
were tricked in to installing a specially crafted extension, an attacker
could potentially exploit these to obtain sensitive information, or bypass
security restrictions. (CVE-2018-5152, CVE-2018-5166)

It was discovered that the web console and JavaScript debugger incorrectly
linkified chrome: and javascript URLs. If a user were tricked in to
clicking a specially crafted link, an attacker could potentially exploit
this to conduct cross-site scripting (XSS) attacks. (CVE-2018-5167)

It was discovered that dragging and dropping link text on to the home
button could set the home page to include chrome pages. If a user were
tricked in to dragging and dropping a specially crafted link on to the
home button, an attacker could potentially exploit this bypass security
restrictions. (CVE-2018-5169)

It was discovered that the Live Bookmarks page and PDF viewer would run
script pasted from the clipboard. If a user were tricked in to copying and
pasting specially crafted text, an attacker could potentially exploit this
to conduct cross-site scripting (XSS) attacks. (CVE-2018-5172)

It was discovered that the JSON viewer incorrectly linkified javascript:
URLs. If a user were tricked in to clicking on a specially crafted link,
an attacker could potentially exploit this to obtain sensitive
information. (CVE-2018-5176)

It was discovered that dragging a file: URL on to a tab that is running in
a different process would cause the file to open in that process. If a
user were tricked in to dragging a file: URL, an attacker could
potentially exploit this to bypass intended security policies.
(CVE-2018-5181)

It was discovered that dragging text that is a file: URL on to the
addressbar would open the specified file. If a user were tricked in to
dragging specially crafted text on to the addressbar, an attacker could
potentially exploit this to bypass intended security policies.
(CVE-2018-5182)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 18.04 LTS:
  firefox                         60.0+build2-0ubuntu1

Ubuntu 17.10:
  firefox                         60.0+build2-0ubuntu0.17.10.1

Ubuntu 16.04 LTS:
  firefox                         60.0+build2-0ubuntu0.16.04.1

Ubuntu 14.04 LTS:
  firefox                         60.0+build2-0ubuntu0.14.04.1

After a standard system update you need to restart Firefox to make
all the necessary changes.

References:
  https://usn.ubuntu.com/usn/usn-3645-1
  CVE-2018-5150, CVE-2018-5151, CVE-2018-5152, CVE-2018-5153,
  CVE-2018-5154, CVE-2018-5155, CVE-2018-5157, CVE-2018-5158,
  CVE-2018-5159, CVE-2018-5160, CVE-2018-5163, CVE-2018-5164,
  CVE-2018-5166, CVE-2018-5167, CVE-2018-5168, CVE-2018-5169,
  CVE-2018-5172, CVE-2018-5173, CVE-2018-5175, CVE-2018-5176,
  CVE-2018-5177, CVE-2018-5180, CVE-2018-5181, CVE-2018-5182

Package Information:
  https://launchpad.net/ubuntu/+source/firefox/60.0+build2-0ubuntu1
  https://launchpad.net/ubuntu/+source/firefox/60.0+build2-0ubuntu0.17.10.1
  https://launchpad.net/ubuntu/+source/firefox/60.0+build2-0ubuntu0.16.04.1
  https://launchpad.net/ubuntu/+source/firefox/60.0+build2-0ubuntu0.14.04.1

- --------------------------------------------------------------------------------

==========================================================================
Ubuntu Security Notice USN-3645-2
May 18, 2018

firefox regression
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- - Ubuntu 18.04 LTS
- - Ubuntu 17.10
- - Ubuntu 16.04 LTS
- - Ubuntu 14.04 LTS

Summary:

USN-3645-1 caused a regression in Firefox.

Software Description:
- - firefox: Mozilla Open Source web browser

Details:

USN-3645-1 fixed vulnerabilities in Firefox. The update caused an issue
where users experienced long UI pauses in some circumsances. This update
fixes the problem.

We apologize for the inconvenience.

Original advisory details:

 Multiple security issues were discovered in Firefox. If a user were
 tricked in to opening a specially crafted website, an attacker could
 potentially exploit these to cause a denial of service via application
 crash, bypass same-origin restrictions, conduct cross-site scripting (XSS)
 attacks, install lightweight themes without user interaction, spoof the
 filename in the downloads panel, or execute arbitrary code.
 (CVE-2018-5150, CVE-2018-5151, CVE-2018-5153, CVE-2018-5154,
 CVE-2018-5155, CVE-2018-5157, CVE-2018-5158, CVE-2018-5159, CVE-2018-5160,
 CVE-2018-5163, CVE-2018-5164, CVE-2018-5168, CVE-2018-5173, CVE-2018-5175,
 CVE-2018-5177, CVE-2018-5180)
 
 Multiple security issues were discovered with WebExtensions. If a user
 were tricked in to installing a specially crafted extension, an attacker
 could potentially exploit these to obtain sensitive information, or bypass
 security restrictions. (CVE-2018-5152, CVE-2018-5166)
 
 It was discovered that the web console and JavaScript debugger incorrectly
 linkified chrome: and javascript URLs. If a user were tricked in to
 clicking a specially crafted link, an attacker could potentially exploit
 this to conduct cross-site scripting (XSS) attacks. (CVE-2018-5167)
 
 It was discovered that dragging and dropping link text on to the home
 button could set the home page to include chrome pages. If a user were
 tricked in to dragging and dropping a specially crafted link on to the
 home button, an attacker could potentially exploit this bypass security
 restrictions. (CVE-2018-5169)
 
 It was discovered that the Live Bookmarks page and PDF viewer would run
 script pasted from the clipboard. If a user were tricked in to copying and
 pasting specially crafted text, an attacker could potentially exploit this
 to conduct cross-site scripting (XSS) attacks. (CVE-2018-5172)
 
 It was discovered that the JSON viewer incorrectly linkified javascript:
 URLs. If a user were tricked in to clicking on a specially crafted link,
 an attacker could potentially exploit this to obtain sensitive
 information. (CVE-2018-5176)
 
 It was discovered that dragging a file: URL on to a tab that is running in
 a different process would cause the file to open in that process. If a
 user were tricked in to dragging a file: URL, an attacker could
 potentially exploit this to bypass intended security policies.
 (CVE-2018-5181)
 
 It was discovered that dragging text that is a file: URL on to the
 addressbar would open the specified file. If a user were tricked in to
 dragging specially crafted text on to the addressbar, an attacker could
 potentially exploit this to bypass intended security policies.
 (CVE-2018-5182)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 18.04 LTS:
  firefox                         60.0.1+build2-0ubuntu0.18.04.1

Ubuntu 17.10:
  firefox                         60.0.1+build2-0ubuntu0.17.10.1

Ubuntu 16.04 LTS:
  firefox                         60.0.1+build2-0ubuntu0.16.04.1

Ubuntu 14.04 LTS:
  firefox                         60.0.1+build2-0ubuntu0.14.04.1

After a standard system update you need to restart Firefox to make
all the necessary changes.

References:
  https://usn.ubuntu.com/usn/usn-3645-2
  https://usn.ubuntu.com/usn/usn-3645-1
  https://launchpad.net/bugs/1772115

Package Information:
  https://launchpad.net/ubuntu/+source/firefox/60.0.1+build2-0ubuntu0.18.04.1
  https://launchpad.net/ubuntu/+source/firefox/60.0.1+build2-0ubuntu0.17.10.1
  https://launchpad.net/ubuntu/+source/firefox/60.0.1+build2-0ubuntu0.16.04.1
  https://launchpad.net/ubuntu/+source/firefox/60.0.1+build2-0ubuntu0.14.04.1

- --------------------------END INCLUDED TEXT--------------------

You have received this e-mail bulletin as a result of your organisation's
registration with AusCERT. The mailing list you are subscribed to is
maintained within your organisation, so if you do not wish to continue
receiving these bulletins you should contact your local IT manager. If
you do not know who that is, please send an email to auscert@auscert.org.au
and we will forward your request to the appropriate person.

NOTE: Third Party Rights
This security bulletin is provided as a service to AusCERT's members.  As
AusCERT did not write the document quoted above, AusCERT has had no control
over its content. The decision to follow or act on information or advice
contained in this security bulletin is the responsibility of each user or
organisation, and should be considered in accordance with your organisation's
site policies and procedures. AusCERT takes no responsibility for consequences
which may arise from following or acting on information or advice contained in
this security bulletin.

NOTE: This is only the original release of the security bulletin.  It may
not be updated when updates to the original are made.  If downloading at
a later date, it is recommended that the bulletin is retrieved directly
from the author's website to ensure that the information is still current.

Contact information for the authors of the original document is included
in the Security Bulletin above.  If you have any questions or need further
information, please contact them directly.

Previous advisories and external security bulletins can be retrieved from:

        https://www.auscert.org.au/bulletins/

===========================================================================
Australian Computer Emergency Response Team
The University of Queensland
Brisbane
Qld 4072

Internet Email: auscert@auscert.org.au
Facsimile:      (07) 3365 7031
Telephone:      (07) 3365 4417 (International: +61 7 3365 4417)
                AusCERT personnel answer during Queensland business hours
                which are GMT+10:00 (AEST).
                On call after hours for member emergencies only.
===========================================================================
-----BEGIN PGP SIGNATURE-----
Comment: http://www.auscert.org.au/render.html?it=1967

iQIVAwUBWwIbDox+lLeg9Ub1AQiHRBAAlKfzJFFDrfGHPjLoJCG8HuLThDjENcNu
6o2DFHPv6APkeATb67fpshraWoaEAO3DUF2ddC9E2hrSrmchSQdi8lDQpY/TUIGT
9WoPbaaNiv+7PqLPr5VR8QPPbWl0i1S/gH/Ntn6gTWz2XR5taBEhQjONEMUaB7gv
URL+C4y+Lf2FaCEcXf6swPxhsbtAPtr32jzmZc0lsmerMlnr7qcfTrqkzO5KyFGF
fQOCWt4xSGbjUQZb47pc49pjUrMAZEWr659qiwEzsSRi2PcTWSobw4mX5sFIWUnJ
e9LUdu5F0IaPWU/kbfTdwKEfP8PClM4v8tDD81eEhTbJCnK8a1UxDjkVSXE0/IfF
Grz4HPw0syM0O1yEMDPI9d+YscfSNUsJANrLLHgFKWvJJk8PUsHXeD2iNgj8nAVb
TIG1utwVeZfH37Sd0lMaOWnjWoQYYaxXAwEI7eov656iTQLedHnNvlCt+APhT4gs
/fM/UYbrmiHoS1FKNXeCpCQgtgwaqB16T4bLM/33I/OWoZe7JQ02LDoSrzMPLqXq
FtERVHJJ5iec9Non2SnIEDQLBQqbhLi9CJjQR2KA5IVYByLidd9Yp+X29tL/N00I
nFy7Qz/xsOZuiDRC1gDXGT/LLUcblYuFqwz5FMnMBWKxaPc3tSDSDbEISTX9YT5C
HNH/9F3RjDY=
=BT0I
-----END PGP SIGNATURE-----

« Back to bulletins