firefox vulnerability

Related Vulnerabilities: CVE-2015-7184  

Firefox could be made to expose sensitive information across origins

Abdulrahman Alqabandi and Ben Kelly discovered that the fetch() API did not correctly implement the Cross Origin Resource Sharing (CORS) specification. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to obtain sensitive information from other origins. (CVE-2015-7184)

16 October 2015

firefox vulnerability

A security issue affects these releases of Ubuntu and its derivatives:

  • Ubuntu 15.04
  • Ubuntu 14.04 LTS
  • Ubuntu 12.04 LTS

Summary

Firefox could be made to expose sensitive information across origins

Software Description

  • firefox - Mozilla Open Source web browser

Details

Abdulrahman Alqabandi and Ben Kelly discovered that the fetch() API did not correctly implement the Cross Origin Resource Sharing (CORS) specification. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to obtain sensitive information from other origins. (CVE-2015-7184)

Update instructions

The problem can be corrected by updating your system to the following package versions:

Ubuntu 15.04
firefox - 41.0.2+build2-0ubuntu0.15.04.1
Ubuntu 14.04 LTS
firefox - 41.0.2+build2-0ubuntu0.14.04.1
Ubuntu 12.04 LTS
firefox - 41.0.2+build2-0ubuntu0.12.04.1

To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades.

After a standard system update you need to restart Firefox to make all the necessary changes.

References