security advisorycriticalcode execution Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code, information disclosure or CSS sanitiser bypass. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-2496-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Emilio Pozuelo Monfort December 16, 2020 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : firefox-esr Version : 78.6.0esr-1~deb9u1 CVE ID : CVE-2020-16042 CVE-2020-26971 CVE-2020-26973 CVE-2020-26974 CVE-2020-26978 CVE-2020-35111 CVE-2020-35113 Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code, information disclosure or CSS sanitiser bypass. For Debian 9 stretch, these problems have been fixed in version 78.6.0esr-1~deb9u1. We recommend that you upgrade your firefox-esr packages. For the detailed security status of firefox-esr please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/firefox-esr Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Debian LTS Advisory DLA-2500-2 addresses several vulnerabilities in OpenSSL. Update to secure your environment.. Debian LTS Advisory, Firefox ESR Update, Mozilla Security Issues. . Severity: Critical. LinuxSecurity.com Team
Dec 16, 2020 •Critical Debian LTS