Debian Security Advisory
DSA-3928-1 firefox-esr -- security update
- Date Reported:
- 10 Aug 2017
- Affected Packages:
- firefox-esr
- Vulnerable:
- Yes
- Security database references:
- In Mitre's CVE dictionary: CVE-2017-7753, CVE-2017-7779, CVE-2017-7784, CVE-2017-7785, CVE-2017-7786, CVE-2017-7787, CVE-2017-7791, CVE-2017-7792, CVE-2017-7798, CVE-2017-7800, CVE-2017-7801, CVE-2017-7802, CVE-2017-7803, CVE-2017-7807, CVE-2017-7809.
- More information:
-
Several security issues have been found in the Mozilla Firefox web browser: Multiple memory safety errors, use-after-frees, buffer overflows and other implementation errors may lead to the execution of arbitrary code, denial of service, bypass of the same-origin policy or incorrect enforcement of CSP.
For the oldstable distribution (jessie), these problems have been fixed in version 52.3.0esr-1~deb8u2.
For the stable distribution (stretch), these problems have been fixed in version 52.3.0esr-1~deb9u1.
We recommend that you upgrade your firefox-esr packages.