Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.1.12.2024.6779.2
Category:Ubuntu Local Security Checks
Title:Ubuntu: Security Advisory (USN-6779-2)
Summary:The remote host is missing an update for the 'firefox' package(s) announced via the USN-6779-2 advisory.
Description:Summary:
The remote host is missing an update for the 'firefox' package(s) announced via the USN-6779-2 advisory.

Vulnerability Insight:
USN-6779-1 fixed vulnerabilities in Firefox. The update introduced
several minor regressions. This update fixes the problem.

Original advisory details:

Multiple security issues were discovered in Firefox. If a user were
tricked into opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service, obtain sensitive
information across domains, or execute arbitrary code. (CVE-2024-4767,
CVE-2024-4768, CVE-2024-4769, CVE-2024-4771, CVE-2024-4772, CVE-2024-4773,
CVE-2024-4774, CVE-2024-4775, CVE-2024-4776, CVE-2024-4777, CVE-2024-4778)

Jan-Ivar Bruaroey discovered that Firefox did not properly manage memory
when audio input connected with multiple consumers. An attacker could
potentially exploit this issue to cause a denial of service, or execute
arbitrary code. (CVE-2024-4764)

Thomas Rinsma discovered that Firefox did not properly handle type check
when handling fonts in PDF.js. An attacker could potentially exploit this
issue to execute arbitrary javascript code in PDF.js. (CVE-2024-4367)

Irvan Kurniawan discovered that Firefox did not properly handle certain
font styles when saving a page to PDF. An attacker could potentially
exploit this issue to cause a denial of service. (CVE-2024-4770)

Affected Software/OS:
'firefox' package(s) on Ubuntu 20.04.

Solution:
Please install the updated package(s).

CVSS Score:
10.0

CVSS Vector:
AV:N/AC:L/Au:N/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2024-4367
https://bugzilla.mozilla.org/show_bug.cgi?id=1893645
https://www.mozilla.org/security/advisories/mfsa2024-21/
https://www.mozilla.org/security/advisories/mfsa2024-22/
https://www.mozilla.org/security/advisories/mfsa2024-23/
https://lists.debian.org/debian-lts-announce/2024/05/msg00010.html
https://lists.debian.org/debian-lts-announce/2024/05/msg00012.html
Common Vulnerability Exposure (CVE) ID: CVE-2024-4764
https://bugzilla.mozilla.org/show_bug.cgi?id=1879093
Common Vulnerability Exposure (CVE) ID: CVE-2024-4767
https://bugzilla.mozilla.org/show_bug.cgi?id=1878577
Common Vulnerability Exposure (CVE) ID: CVE-2024-4768
https://bugzilla.mozilla.org/show_bug.cgi?id=1886082
Common Vulnerability Exposure (CVE) ID: CVE-2024-4769
https://bugzilla.mozilla.org/show_bug.cgi?id=1886108
Common Vulnerability Exposure (CVE) ID: CVE-2024-4770
https://bugzilla.mozilla.org/show_bug.cgi?id=1893270
Common Vulnerability Exposure (CVE) ID: CVE-2024-4771
https://bugzilla.mozilla.org/show_bug.cgi?id=1893891
Common Vulnerability Exposure (CVE) ID: CVE-2024-4772
https://bugzilla.mozilla.org/show_bug.cgi?id=1870579
Common Vulnerability Exposure (CVE) ID: CVE-2024-4773
https://bugzilla.mozilla.org/show_bug.cgi?id=1875248
Common Vulnerability Exposure (CVE) ID: CVE-2024-4774
https://bugzilla.mozilla.org/show_bug.cgi?id=1886598
Common Vulnerability Exposure (CVE) ID: CVE-2024-4775
https://bugzilla.mozilla.org/show_bug.cgi?id=1887332
Common Vulnerability Exposure (CVE) ID: CVE-2024-4776
https://bugzilla.mozilla.org/show_bug.cgi?id=1887343
Common Vulnerability Exposure (CVE) ID: CVE-2024-4777
Memory safety bugs fixed in Firefox 126, Firefox ESR 115.11, and Thunderbird 115.11
https://bugzilla.mozilla.org/buglist.cgi?bug_id=1878199%2C1893340
Common Vulnerability Exposure (CVE) ID: CVE-2024-4778
Memory safety bugs fixed in Firefox 126
https://bugzilla.mozilla.org/buglist.cgi?bug_id=1838834%2C1889291%2C1889595%2C1890204%2C1891545
CopyrightCopyright (C) 2024 Greenbone AG

This is only one of 146377 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.