Publication Date: 14 October 2014 Vulnerability Overview: Firefox could be made to crash or run programs as your login if it opened a malicious website. Affected Packages: Firefox - Mozilla Open Source web browser Vulnerability Details: - Multiple memory safety issues were discovered in Firefox by several researchers. - A buffer overflow was found during CSS manipulation by Ake Kettunen. - Holger Fuehrmannek discovered additional issues. CVE References: CVE-2014-1574, CVE-2014-1575, CVE-2014-1576, CVE-2014-1577, CVE-2014-1578, CVE-2014-1580, CVE-2014-1581, CVE-2014-1582, CVE-2014-1583, CVE-2014-1584, CVE-2014-1585, CVE-2014-1586 Update Instructions: After a standard system update, you need to restart Firefox to make all the necessary changes. The affected package versions are: - For Ubuntu 14.04 LTS: firefox - 33.0+build2-0ubuntu0.14.04.1 - For Ubuntu 12.04: firefox - 33.0+build2-0ubuntu0.12.04.1 Related Notices: USN-2373-1