Alerts This Week
Warning Icon 1 684
Alerts This Week
Warning Icon 1 684

Debian: DSA-3457-1 Critical: Iceweasel Buffer Overflow and TLS Attack

debian
Calendar Grey January 27, 2016
Debian Logo
Numerous vulnerabilities in Firefox may permit unauthorized code execution. Urgent update advised across all platforms.
Multiple security issues have been found in Iceweasel, Debian's version of the Mozilla Firefox web browser: Multiple memory safety errors and a buffer overflow may lead to the exec...

Summary

Multiple security issues have been found in Iceweasel, Debian's version
of the Mozilla Firefox web browser: Multiple memory safety errors and a
buffer overflow may lead to the execution of arbitrary code. In addition
the bundled NSS crypto library addresses the SLOTH attack on TLS 1.2.

For the oldstable distribution (wheezy), these problems have been fixed
in version 38.6.0esr-1~deb7u1.

For the stable distribution (jessie), these problems have been fixed in
version 38.6.0esr-1~deb8u1.

For the unstable distribution (sid), these problems have been fixed in
version 44.0-1.

We recommend that you upgrade your iceweasel packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/



Severity
critical
Lowest
Low
Medium
High
Critical

Package: iceweasel
CVE ID: CVE-2015-7575 CVE-2016-1930 CVE-2016-1935

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here