Thursday, December 13, 2012

[USN-1665-1] unity-firefox-extension vulnerability

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.11 (GNU/Linux)
Comment: Using GnuPG with undefined - http://www.enigmail.net/

iQIcBAEBCgAGBQJQyejvAAoJEGVp2FWnRL6T3OYQAJO+hPT1PESrc5fqjfJT5uLF
ZBaeTryrxMm2+u6Kq83paDgOiB45fVIxMTGcv9VPc2a7UAKVrCwu8j3oOupN//8f
DkvDwI4rnhKZV0dwOYgKDkkaG1YMYgIf5lSvVtG/0tS0dTX6L/4DwII9y7jBD2Sw
Fyp/F2e5+6c+C0qwF4JNHFY+uHu25UFokXDhju96GWkIQ8VFtlVXmbEdG+sgTOio
Sy5Sy5aL9lqsUiBOMVn+YMzwDgyAT3H90Sz+zSzM8/3fbZzdvpR1cCO4GW4B452z
0zgEX5n07fq80Plg5BkQ+mRm7zzpSnZFkBGZDjRzUNQUpQcyqiiH62qE2l0xhW2y
rft4x5IznR8JZceeC5FSqAFTx+6vwDTcV26qG1qoKWMXHgSml5MVYN3rnvrb7ZDy
PF7AZvBofDWmX1WvwWxuS8g24kLt3Syno4j5ioZWMPSnvfBEaof7FaiB3AbPHJUH
C7X3voZInpyYdlS0VexI1m72z4VJM9+asQ6jGFzjGOQdqF/pGzR3xAFLn1eR1wyN
op0XQmTxfNTbN00Cq98uq4ASkveB2qX9T+I1OV3LXYoL7e+NHFcqpb+SMP/eVvyF
XezJ37AhsIcZnwYCiTuU+VG23BY+Ql+QE1tEsO5rSN0vsBvMV/8C7U9ct9YzCaWX
jfK3jyuy2TOdgYZJgeb7
=JWtc
-----END PGP SIGNATURE-----
==========================================================================
Ubuntu Security Notice USN-1665-1
December 13, 2012

unity-firefox-extension vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 12.10

Summary:

unity-firefox-extension could be made to expose sensitive information over
the network.

Software Description:
- unity-firefox-extension: Firefox extension: Unity Integration

Details:

It was discovered that unity-firefox-extension bypassed the same origin
policy checks in certain circumstances. If a user were tricked into opening
a malicious page, an attacker could exploit this to steal confidential data
or perform other security-sensitive operations.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 12.10:
xul-ext-unity 2.4.1-0ubuntu1.2

After a standard system update you need to restart Firefox to make all the
necessary changes.

References:
http://www.ubuntu.com/usn/usn-1665-1
CVE-2012-0958

Package Information:

https://launchpad.net/ubuntu/+source/unity-firefox-extension/2.4.1-0ubuntu1.2

No comments:

Post a Comment