Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

Debian Wheezy DSA-3000-1: Critical Iceweasel Remote Issues Fixed

debian
Calendar Grey June 2, 2013
Debian Logo
Numerous safety patches for Iceweasel tackling significant memory and input vulnerabilities to avert remote exploitation.
Multiple security issues have been found in Iceweasel, Debian's version of the Mozilla Firefox web browser: Multiple memory safety errors, missing input sanitising vulnerabilities,...

Summary

Multiple security issues have been found in Iceweasel, Debian's version
of the Mozilla Firefox web browser: Multiple memory safety errors,
missing input sanitising vulnerabilities, use-after-free vulnerabilities,
buffer overflows and other programming errors may lead to the execution
of arbitrary code, privilege escalation, information leaks or
cross-site-scripting.

We're changing the approach for security updates for Iceweasel, Icedove
and Iceape in stable-security: Instead of backporting security fixes,
we now provide releases based on the Extended Support Release branch. As
such, this update introduces packages based on Firefox 17 and at some
point in the future we will switch to the next ESR branch once ESR 17
has reached it's end of life.

Some Xul extensions currently packaged in the Debian archive are not
compatible with the new browser engine. Up-to-date and compatible
versions can be retrieved from https://addons.mozilla.org/en-US/firefox/ as a short
term solution. A solution t...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: iceweasel
CVE ID: CVE-2013-0773 CVE-2013-0775 CVE-2013-0776 CVE-2013-0780

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here