Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

Debian: DSA-3050-3 Moderate: Iceweasel Buffer Overflow and DoS Fix

debian
Calendar Grey November 12, 2014
Debian Logo
The Debian Security Team has released an advisory to enhance iceweasel with crucial security fixes and architectural refinements.
The previous update for iceweasel in DSA-3050-1 did not contain builds for the armhf architecture due to an error in the Debian packaging specific to the armhf build

Summary

Multiple security issues have been found in Iceweasel, Debian's version
of the Mozilla Firefox web browser: Multiple memory safety errors,
buffer overflows, use-after-frees and other implementation errors may
lead to the execution of arbitrary code, denial of service, the bypass
of the same-origin policy or a loss of privacy.

This update updates Iceweasel to the ESR31 series of Firefox. The new
release introduces a new user interface.

In addition, this update also disables SSLv3.

For the stable distribution (wheezy), this problem has been fixed
in version 31.2.0esr-3~deb7u1.

We recommend that you upgrade your iceweasel packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/



Package: iceweasel
CVE ID: CVE-2014-1574 CVE-2014-1576 CVE-2014-1577 CVE-2014-1578

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here