USN-4140-1: Firefox vulnerability

25 September 2019

firefox vulnerability

A security issue affects these releases of Ubuntu and its derivatives:

  • Ubuntu 19.04
  • Ubuntu 18.04 LTS
  • Ubuntu 16.04 LTS

Summary

Firefox could be made to hijack the mouse pointer it if opened a malicious website.

Software Description

  • firefox - Mozilla Open Source web browser

Details

It was discovered that no user notification was given when pointer lock is enabled. If a user were tricked in to opening a specially crafted website, an attacker could potentially exploit this to hijack the mouse pointer and confuse users.

Update instructions

The problem can be corrected by updating your system to the following package versions:

Ubuntu 19.04
firefox - 69.0.1+build1-0ubuntu0.19.04.1
Ubuntu 18.04 LTS
firefox - 69.0.1+build1-0ubuntu0.18.04.1
Ubuntu 16.04 LTS
firefox - 69.0.1+build1-0ubuntu0.16.04.1

To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades.

After a standard system update you need to restart Firefox to make all the necessary changes.

References