Lucene search

K
ubuntuUbuntuUSN-6320-1
HistoryAug 30, 2023 - 12:00 a.m.

Firefox vulnerabilities

2023-08-3000:00:00
ubuntu.com
51
mozilla open source
ubuntu 20.04 lts
denial of service
sensitive information
arbitrary code
memory management
spoofing attacks
push notifications

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

AI Score

8.8

Confidence

Low

EPSS

0.002

Percentile

59.6%

Releases

  • Ubuntu 20.04 LTS

Packages

  • firefox - Mozilla Open Source web browser

Details

Multiple security issues were discovered in Firefox. If a user were
tricked into opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service, obtain sensitive
information across domains, or execute arbitrary code. (CVE-2023-4573,
CVE-2023-4574, CVE-2023-4575, CVE-2023-4578, CVE-2023-4581, CVE-2023-4583,
CVE-2023-4584, CVE-2023-4585)

Lukas Bernhard discovered that Firefox did not properly manage memory when
the β€œUpdateRegExpStatics” attempted to access β€œinitialStringHeap”. An
attacker could potentially exploit this issue to cause a denial of service.
(CVE-2023-4577)

Malte JΓΌrgens discovered that Firefox did not properly handle search
queries if the search query itself was a well formed URL. An attacker could
potentially exploit this issue to perform spoofing attacks. (CVE-2023-4579)

Harveer Singh discovered that Firefox did not properly handle push
notifications stored on disk in private browsing mode. An attacker could
potentially exploits this issue to access sensitive information.
(CVE-2023-4580)

OSVersionArchitecturePackageVersionFilename
Ubuntu20.04noarchfirefox<Β 117.0+build2-0ubuntu0.20.04.1UNKNOWN
Ubuntu20.04noarchfirefox-dbg<Β 117.0+build2-0ubuntu0.20.04.1UNKNOWN
Ubuntu20.04noarchfirefox-dev<Β 117.0+build2-0ubuntu0.20.04.1UNKNOWN
Ubuntu20.04noarchfirefox-geckodriver<Β 117.0+build2-0ubuntu0.20.04.1UNKNOWN
Ubuntu20.04noarchfirefox-locale-af<Β 117.0+build2-0ubuntu0.20.04.1UNKNOWN
Ubuntu20.04noarchfirefox-locale-an<Β 117.0+build2-0ubuntu0.20.04.1UNKNOWN
Ubuntu20.04noarchfirefox-locale-ar<Β 117.0+build2-0ubuntu0.20.04.1UNKNOWN
Ubuntu20.04noarchfirefox-locale-as<Β 117.0+build2-0ubuntu0.20.04.1UNKNOWN
Ubuntu20.04noarchfirefox-locale-ast<Β 117.0+build2-0ubuntu0.20.04.1UNKNOWN
Ubuntu20.04noarchfirefox-locale-az<Β 117.0+build2-0ubuntu0.20.04.1UNKNOWN
Rows per page:
1-10 of 991

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

AI Score

8.8

Confidence

Low

EPSS

0.002

Percentile

59.6%