USN-6747-2

Source
https://ubuntu.com/security/notices/USN-6747-2
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/USN-6747-2.json
Published
2024-05-02T03:20:32.197220Z
Modified
2024-05-02T03:20:32.197220Z
Summary
firefox regressions
Details

USN-6747-1 fixed vulnerabilities in Firefox. The update introduced several minor regressions. This update fixes the problem.

Original advisory details:

Multiple security issues were discovered in Firefox. If a user were tricked into opening a specially crafted website, an attacker could potentially exploit these to cause a denial of service, obtain sensitive information across domains, or execute arbitrary code. (CVE-2024-3852, CVE-2024-3864, CVE-2024-3865)

Bartek Nowotarski discovered that Firefox did not properly limit HTTP/2 CONTINUATION frames. An attacker could potentially exploit this issue to cause a denial of service. (CVE-2024-3302)

Gary Kwong discovered that Firefox did not properly manage memory when running garbage collection during realm initialization. An attacker could potentially exploit this issue to cause a denial of service, or execute arbitrary code. (CVE-2024-3853)

Lukas Bernhard discovered that Firefox did not properly manage memory during JIT optimisations, leading to an out-of-bounds read vulnerability. An attacker could possibly use this issue to cause a denial of service or expose sensitive information. (CVE-2024-3854, CVE-2024-3855)

Nan Wang discovered that Firefox did not properly manage memory during WASM garbage collection. An attacker could potentially exploit this issue to cause a denial of service, or execute arbitrary code. (CVE-2024-3856)

Lukas Bernhard discovered that Firefox did not properly manage memory when handling JIT created code during garbage collection. An attacker could potentially exploit this issue to cause a denial of service, or execute arbitrary code. (CVE-2024-3857)

Lukas Bernhard discovered that Firefox did not properly manage memory when tracing in JIT. An attacker could potentially exploit this issue to cause a denial of service. (CVE-2024-3858)

Ronald Crane discovered that Firefox did not properly manage memory in the OpenType sanitizer on 32-bit devices, leading to an out-of-bounds read vulnerability. An attacker could possibly use this issue to cause a denial of service or expose sensitive information. (CVE-2024-3859)

Garry Kwong discovered that Firefox did not properly manage memory when tracing empty shape lists in JIT. An attacker could potentially exploit this issue to cause a denial of service. (CVE-2024-3860)

Ronald Crane discovered that Firefox did not properly manage memory when handling an AlignedBuffer. An attacker could potentially exploit this issue to cause denial of service, or execute arbitrary code. (CVE-2024-3861)

Ronald Crane discovered that Firefox did not properly manage memory when handling code in MarkStack. An attacker could possibly use this issue to cause a denial of service or execute arbitrary code. (CVE-2024-3862)

References

Affected packages

Ubuntu:20.04:LTS / firefox

Package

Name
firefox

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0The exact introduced commit is unknown
Fixed
125.0.3+build1-0ubuntu0.20.04.1

Ecosystem specific

{
    "availability": "No subscription needed",
    "binaries": [
        {
            "firefox-locale-de": "125.0.3+build1-0ubuntu0.20.04.1",
            "firefox-locale-nl": "125.0.3+build1-0ubuntu0.20.04.1",
            "firefox-locale-kn": "125.0.3+build1-0ubuntu0.20.04.1",
            "firefox-locale-gl": "125.0.3+build1-0ubuntu0.20.04.1",
            "firefox-locale-fy": "125.0.3+build1-0ubuntu0.20.04.1",
            "firefox-locale-eo": "125.0.3+build1-0ubuntu0.20.04.1",
            "firefox-locale-km": "125.0.3+build1-0ubuntu0.20.04.1",
            "firefox-locale-or": "125.0.3+build1-0ubuntu0.20.04.1",
            "firefox-locale-az": "125.0.3+build1-0ubuntu0.20.04.1",
            "firefox-locale-lt": "125.0.3+build1-0ubuntu0.20.04.1",
            "firefox-locale-hy": "125.0.3+build1-0ubuntu0.20.04.1",
            "firefox-locale-kk": "125.0.3+build1-0ubuntu0.20.04.1",
            "firefox-locale-sv": "125.0.3+build1-0ubuntu0.20.04.1",
            "firefox-locale-uk": "125.0.3+build1-0ubuntu0.20.04.1",
            "firefox-locale-sr": "125.0.3+build1-0ubuntu0.20.04.1",
            "firefox-locale-ca": "125.0.3+build1-0ubuntu0.20.04.1",
            "firefox-locale-is": "125.0.3+build1-0ubuntu0.20.04.1",
            "firefox-locale-ne": "125.0.3+build1-0ubuntu0.20.04.1",
            "firefox-locale-ga": "125.0.3+build1-0ubuntu0.20.04.1",
            "firefox-locale-it": "125.0.3+build1-0ubuntu0.20.04.1",
            "firefox-locale-ja": "125.0.3+build1-0ubuntu0.20.04.1",
            "firefox-locale-lg": "125.0.3+build1-0ubuntu0.20.04.1",
            "firefox-locale-ms": "125.0.3+build1-0ubuntu0.20.04.1",
            "firefox-dev": "125.0.3+build1-0ubuntu0.20.04.1",
            "firefox-locale-ia": "125.0.3+build1-0ubuntu0.20.04.1",
            "firefox-locale-ko": "125.0.3+build1-0ubuntu0.20.04.1",
            "firefox-locale-hr": "125.0.3+build1-0ubuntu0.20.04.1",
            "firefox-locale-mai": "125.0.3+build1-0ubuntu0.20.04.1",
            "firefox-locale-nb": "125.0.3+build1-0ubuntu0.20.04.1",
            "firefox-mozsymbols": "125.0.3+build1-0ubuntu0.20.04.1",
            "firefox-locale-vi": "125.0.3+build1-0ubuntu0.20.04.1",
            "firefox-locale-zh-hans": "125.0.3+build1-0ubuntu0.20.04.1",
            "firefox-locale-he": "125.0.3+build1-0ubuntu0.20.04.1",
            "firefox-locale-sw": "125.0.3+build1-0ubuntu0.20.04.1",
            "firefox-locale-el": "125.0.3+build1-0ubuntu0.20.04.1",
            "firefox-locale-oc": "125.0.3+build1-0ubuntu0.20.04.1",
            "firefox-locale-xh": "125.0.3+build1-0ubuntu0.20.04.1",
            "firefox-locale-tg": "125.0.3+build1-0ubuntu0.20.04.1",
            "firefox-locale-nn": "125.0.3+build1-0ubuntu0.20.04.1",
            "firefox-locale-csb": "125.0.3+build1-0ubuntu0.20.04.1",
            "firefox-locale-ar": "125.0.3+build1-0ubuntu0.20.04.1",
            "firefox-locale-cs": "125.0.3+build1-0ubuntu0.20.04.1",
            "firefox-locale-gn": "125.0.3+build1-0ubuntu0.20.04.1",
            "firefox-locale-hsb": "125.0.3+build1-0ubuntu0.20.04.1",
            "firefox-locale-zu": "125.0.3+build1-0ubuntu0.20.04.1",
            "firefox-locale-my": "125.0.3+build1-0ubuntu0.20.04.1",
            "firefox-locale-ro": "125.0.3+build1-0ubuntu0.20.04.1",
            "firefox-geckodriver": "125.0.3+build1-0ubuntu0.20.04.1",
            "firefox-locale-szl": "125.0.3+build1-0ubuntu0.20.04.1",
            "firefox-locale-af": "125.0.3+build1-0ubuntu0.20.04.1",
            "firefox-locale-sk": "125.0.3+build1-0ubuntu0.20.04.1",
            "firefox-locale-nso": "125.0.3+build1-0ubuntu0.20.04.1",
            "firefox-locale-si": "125.0.3+build1-0ubuntu0.20.04.1",
            "firefox": "125.0.3+build1-0ubuntu0.20.04.1",
            "firefox-locale-cy": "125.0.3+build1-0ubuntu0.20.04.1",
            "firefox-locale-fa": "125.0.3+build1-0ubuntu0.20.04.1",
            "firefox-locale-cak": "125.0.3+build1-0ubuntu0.20.04.1",
            "firefox-locale-sq": "125.0.3+build1-0ubuntu0.20.04.1",
            "firefox-locale-en": "125.0.3+build1-0ubuntu0.20.04.1",
            "firefox-locale-tr": "125.0.3+build1-0ubuntu0.20.04.1",
            "firefox-locale-br": "125.0.3+build1-0ubuntu0.20.04.1",
            "firefox-locale-et": "125.0.3+build1-0ubuntu0.20.04.1",
            "firefox-locale-ast": "125.0.3+build1-0ubuntu0.20.04.1",
            "firefox-locale-th": "125.0.3+build1-0ubuntu0.20.04.1",
            "firefox-locale-da": "125.0.3+build1-0ubuntu0.20.04.1",
            "firefox-locale-fi": "125.0.3+build1-0ubuntu0.20.04.1",
            "firefox-locale-ku": "125.0.3+build1-0ubuntu0.20.04.1",
            "firefox-locale-mn": "125.0.3+build1-0ubuntu0.20.04.1",
            "firefox-locale-ru": "125.0.3+build1-0ubuntu0.20.04.1",
            "firefox-locale-mk": "125.0.3+build1-0ubuntu0.20.04.1",
            "firefox-locale-bg": "125.0.3+build1-0ubuntu0.20.04.1",
            "firefox-locale-hu": "125.0.3+build1-0ubuntu0.20.04.1",
            "firefox-locale-gu": "125.0.3+build1-0ubuntu0.20.04.1",
            "firefox-locale-bn": "125.0.3+build1-0ubuntu0.20.04.1",
            "firefox-locale-kab": "125.0.3+build1-0ubuntu0.20.04.1",
            "firefox-locale-ml": "125.0.3+build1-0ubuntu0.20.04.1",
            "firefox-locale-an": "125.0.3+build1-0ubuntu0.20.04.1",
            "firefox-locale-be": "125.0.3+build1-0ubuntu0.20.04.1",
            "firefox-locale-eu": "125.0.3+build1-0ubuntu0.20.04.1",
            "firefox-locale-fr": "125.0.3+build1-0ubuntu0.20.04.1",
            "firefox-locale-pa": "125.0.3+build1-0ubuntu0.20.04.1",
            "firefox-locale-as": "125.0.3+build1-0ubuntu0.20.04.1",
            "firefox-locale-id": "125.0.3+build1-0ubuntu0.20.04.1",
            "firefox-locale-mr": "125.0.3+build1-0ubuntu0.20.04.1",
            "firefox-locale-bs": "125.0.3+build1-0ubuntu0.20.04.1",
            "firefox-locale-te": "125.0.3+build1-0ubuntu0.20.04.1",
            "firefox-locale-lv": "125.0.3+build1-0ubuntu0.20.04.1",
            "firefox-locale-ka": "125.0.3+build1-0ubuntu0.20.04.1",
            "firefox-locale-ta": "125.0.3+build1-0ubuntu0.20.04.1",
            "firefox-locale-gd": "125.0.3+build1-0ubuntu0.20.04.1",
            "firefox-locale-zh-hant": "125.0.3+build1-0ubuntu0.20.04.1",
            "firefox-locale-uz": "125.0.3+build1-0ubuntu0.20.04.1",
            "firefox-locale-hi": "125.0.3+build1-0ubuntu0.20.04.1",
            "firefox-locale-es": "125.0.3+build1-0ubuntu0.20.04.1",
            "firefox-locale-ur": "125.0.3+build1-0ubuntu0.20.04.1",
            "firefox-locale-pl": "125.0.3+build1-0ubuntu0.20.04.1",
            "firefox-locale-pt": "125.0.3+build1-0ubuntu0.20.04.1",
            "firefox-locale-sl": "125.0.3+build1-0ubuntu0.20.04.1"
        }
    ]
}