Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

Debian 8 DSA-3600-1 Critical: Firefox-ESR Buffer Overflow Threats

debian
Calendar Grey June 9, 2016
Scroller Debian
Security Update DSA-4500-1 outlines several vulnerabilities within the Chrome browser, encompassing heap corruption and integer overflows.
Multiple security issues have been found in the Mozilla Firefox web browser: Multiple memory safety errors, buffer overflows and other implementation errors may lead to the executi...

Summary

Multiple security issues have been found in the Mozilla Firefox web
browser: Multiple memory safety errors, buffer overflows and other
implementation errors may lead to the execution of arbitrary code or
spoofing.

Wait, Firefox? No more references to Iceweasel? That's right, Debian no
longer applies a custom branding. Please see these links for further
information:
https://glandium.org/blog/?p=3622
https://en.wikipedia.org/wiki/Mozilla_software_rebranded_by_Debian

Debian follows the extended support releases (ESR) of Firefox. Support
for the 38.x series has ended, so starting with this update we're now
following the 45.x releases and this update to the next ESR is also the
point where we reapply the original branding.

Transition packages for the iceweasel packages are provided which
automatically upgrade to the new version. Since new binary packages need
to be installed, make sure to allow that in your upgrade procedure (e.g.
by using "apt-get dist-upgrade" instead of "apt-get upgrade").

For the s...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: firefox-esr
CVE ID: CVE-2016-2818 CVE-2016-2819 CVE-2016-2821 CVE-2016-2822

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.