Referenced CVEs:
CVE-2009-3070, CVE-2009-3071, CVE-2009-3072, CVE-2009-3074, CVE-2009-3075, CVE-2009-3076, CVE-2009-3077, CVE-2009-3078, CVE-2009-3079
Description:
===========================================================Ubuntu Security Notice USN-821-1 September 10, 2009firefox-3.0, xulrunner-1.9 vulnerabilitiesCVE-2009-3070, CVE-2009-3071, CVE-2009-3072, CVE-2009-3074,CVE-2009-3075, CVE-2009-3076, CVE-2009-3077, CVE-2009-3078,CVE-2009-3079===========================================================A security issue affects the following Ubuntu releases:Ubuntu 8.04 LTSUbuntu 8.10Ubuntu 9.04This advisory also applies to the corresponding versions ofKubuntu, Edubuntu, and Xubuntu.The problem can be corrected by upgrading your system to thefollowing package versions:Ubuntu 8.04 LTS: firefox-3.0 3.0.14+build2+nobinonly-0ubuntu0.8.04.1 xulrunner-1.9 1.9.0.14+build2+nobinonly-0ubuntu0.8.04.1Ubuntu 8.10: abrowser 3.0.14+build2+nobinonly-0ubuntu0.8.10.1 firefox-3.0 3.0.14+build2+nobinonly-0ubuntu0.8.10.1 xulrunner-1.9 1.9.0.14+build2+nobinonly-0ubuntu0.8.10.1Ubuntu 9.04: abrowser 3.0.14+build2+nobinonly-0ubuntu0.9.04.1 firefox-3.0 3.0.14+build2+nobinonly-0ubuntu0.9.04.1 xulrunner-1.9 1.9.0.14+build2+nobinonly-0ubuntu0.9.04.1After a standard system upgrade you need to restart Firefox and anyapplications that use xulrunner, such as Epiphany, to effect the necessarychanges.Details follow:Several flaws were discovered in the Firefox browser and JavaScriptengines. If a user were tricked into viewing a malicious website, a remoteattacker could cause a denial of service or possibly execute arbitrary codewith the privileges of the user invoking the program. (CVE-2009-3070,CVE-2009-3071, CVE-2009-3072, CVE-2009-3074, CVE-2009-3075)Jesse Ruderman and Dan Kaminsky discovered that Firefox did not adequatelyinform users when security modules were added or removed via PKCS11. Ifa user visited a malicious website, an attacker could exploit this totrick the user into installing a malicious PKCS11 module. (CVE-2009-3076)It was discovered that Firefox did not properly manage memory when usingXUL tree elements. If a user were tricked into viewing a malicious website,a remote attacker could cause a denial of service or possibly executearbitrary code with the privileges of the user invoking the program.(CVE-2009-3077)Juan Pablo Lopez Yacubian discovered that Firefox did properly displaycertain Unicode characters in the location bar and other text fields whenusing a certain non-Ubuntu font. If a user configured Firefox to use thisfont, an attacker could exploit this to spoof the location bar, such as ina phishing attack. (CVE-2009-3078)It was discovered that the BrowserFeedWriter in Firefox could be subvertedto run JavaScript code from web content with elevated chrome privileges.If a user were tricked into viewing a malicious website, an attacker couldexploit this to execute arbitrary code with the privileges of the userinvoking the program. (CVE-2009-3079)
More...