Headline
Debian Security Advisory 5783-1
Debian Linux Security Advisory 5783-1 - Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code.
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Debian Security Advisory DSA-5783-1 [email protected]
https://www.debian.org/security/ Moritz Muehlenhoff
October 04, 2024 https://www.debian.org/security/faq
Package : firefox-esr
CVE ID : CVE-2024-9392 CVE-2024-9393 CVE-2024-9394 CVE-2024-9401
Multiple security issues have been found in the Mozilla Firefox
web browser, which could potentially result in the execution
of arbitrary code.
Debian follows the extended support releases (ESR) of Firefox.
Starting with this update we’re now following the 128.x releases.
Between 115.x and 128.x, Firefox has seen a number of feature
updates. For more information please refer to
https://www.mozilla.org/en-US/firefox/128.0esr/releasenotes/
For the stable distribution (bookworm), these problems have been fixed in
version 128.3.0esr-1~deb12u1.
We recommend that you upgrade your firefox-esr packages.
For the detailed security status of firefox-esr please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/firefox-esr
Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/
Mailing list: [email protected]
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAmcANaYACgkQEMKTtsN8
TjbVTxAAiGB8YD+VvINzF3/vvN1QMf5RT0QqmEtawGI+SWCWClfzT1zqPTvKDNId
vAo5r/h1GsGNP+GwEqQu3GTn6GUsX6lzXidxtt3OCleWDzPIZCcFEJLRkvyzus0n
cERDOEw77EQ63gQcduJvCt0ZClOVzaOgY+9m8IdkZK+n7WPKse/Ey6dI/A+//d5J
gszktzRrIYNs+09X3yfmeJB1yn3oELNLGiL0KMmJ0Ck2+QToPKIz5wh0jMtirNuV
pKMdM8sWkqPyKElTvoRvcDMpXW+cySaQyZlDWy2P9JdYJlm6HBHzLNE0TQbtrJmq
IGK2XABgBn4QtDie+7OJk/QYm3sRpJotIWUrrYp5h3ZYK8p3nBpGKE/OBqNLlERQ
TJCm8jT+pkHRhk1dJtbH3q30qjv5J0WY58a9GWGshh8JG+itPf/NHyMLE9aKoX+2
/iDfjU8ENJcGXWBDxW2qu6KX4pkSKEkq5g/3M9Z6GG5Iucnw30On+DWxsTSGT6Ur
8oIpRkrLL2nTx1FPUSz8cYH0GK7yDWRf4v+uEr93wDZhKkqIEiF+grRvom1s9bti
ptgA7Thwm3r8dJvDQM01RCeNwRMRrkGBP1l/cWHZ0CBEJqEq3JS93pE7M9PDd/Jr
MEm86whIZWHq6N3ql0fC1ATrALfvyVvQZFdjXFF5VUu1WbMRpDI=
=0Mtj
-----END PGP SIGNATURE-----
Related news
Red Hat Security Advisory 2024-8169-03 - An update for thunderbird is now available for Red Hat Enterprise Linux 8.6 Telecommunications Update Service. Issues addressed include bypass and denial of service vulnerabilities.
Red Hat Security Advisory 2024-8166-03 - An update for thunderbird is now available for Red Hat Enterprise Linux 8.8 Extended Update Support. Issues addressed include bypass, denial of service, and use-after-free vulnerabilities.
Debian Linux Security Advisory 5789-1 - Multiple security issues were discovered in Thunderbird, which could result in the execution of arbitrary code.
Red Hat Security Advisory 2024-7856-03 - An update for thunderbird is now available for Red Hat Enterprise Linux 8.2 Advanced Update Support. Issues addressed include bypass and denial of service vulnerabilities.
Red Hat Security Advisory 2024-7854-03 - An update for thunderbird is now available for Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions, and Red Hat Enterprise Linux 8.4 Telecommunications Update Service. Issues addressed include bypass and denial of service vulnerabilities.
Red Hat Security Advisory 2024-7855-03 - An update for thunderbird is now available for Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions. Issues addressed include bypass and denial of service vulnerabilities.
Red Hat Security Advisory 2024-7853-03 - An update for thunderbird is now available for Red Hat Enterprise Linux 9.2 Extended Update Support. Issues addressed include bypass and denial of service vulnerabilities.
Red Hat Security Advisory 2024-7842-03 - An update for firefox is now available for Red Hat Enterprise Linux 8.8 Extended Update Support. Issues addressed include bypass and denial of service vulnerabilities.
Red Hat Security Advisory 2024-7704-03 - An update for firefox is now available for Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions, and Red Hat Enterprise Linux 8.6 Telecommunications Update Service. Issues addressed include bypass and denial of service vulnerabilities.
Red Hat Security Advisory 2024-7703-03 - An update for firefox is now available for Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 8.4 Update Services for SAP Solutions, and Red Hat Enterprise Linux 8.4 Telecommunications Update Service. Issues addressed include bypass and denial of service vulnerabilities.
Red Hat Security Advisory 2024-7702-03 - An update for firefox is now available for Red Hat Enterprise Linux 7 Extended Lifecycle Support. Issues addressed include bypass and denial of service vulnerabilities.
Ubuntu Security Notice 7056-1 - Multiple security issues were discovered in Firefox. If a user were tricked into opening a specially crafted website, an attacker could potentially exploit these to cause a denial of service, obtain sensitive information across domains, or execute arbitrary code. Masato Kinugawa discovered that Firefox did not properly validate javascript under the "resource://pdf.js" origin. An attacker could potentially exploit this issue to execute arbitrary javascript code and access cross-origin PDF content.