lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [day] [month] [year] [list]
Date: Thu, 9 Mar 2017 23:36:56 +0100
From: Moritz Muehlenhoff <jmm@...ian.org>
To: bugtraq@...urityfocus.com
Subject: [SECURITY] [DSA 3805-1] firefox-esr security update

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

- -------------------------------------------------------------------------
Debian Security Advisory DSA-3805-1                   security@...ian.org
https://www.debian.org/security/                       Moritz Muehlenhoff
March 08, 2017                        https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package        : firefox-esr
CVE ID         : CVE-2017-5398 CVE-2017-5400 CVE-2017-5401 CVE-2017-5402 
                 CVE-2017-5404 CVE-2017-5405 CVE-2017-5407 CVE-2017-5408 
                 CVE-2017-5410

Multiple security issues have been found in the Mozilla Firefox web
browser: Multiple memory safety errors, use-after-frees and other
implementation errors may lead to the execution of arbitrary code, ASLR
bypass, information disclosure or denial of service.
 
For the stable distribution (jessie), these problems have been fixed in
version 45.8.0esr-1~deb8u1.

For the unstable distribution (sid), these problems have been fixed in
version 45.8.0esr-1 of firefox-esr and version 52.0-1 of firefox.

We recommend that you upgrade your firefox-esr packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: debian-security-announce@...ts.debian.org
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAljAfiwACgkQEMKTtsN8
TjbR4A/+NVBGR+lG1nx3tzAXODPTbvp+jG/MZwgS6Zs+jZ9b0QYeSsZZgiSC43JH
p2cRP5QdwdGeOCLFEsT6ooKv5IqxiOR6fmDDEARNnuN28IGrhg7tNxFDM/z3Wlbw
Hi8LD5GeGITn/ssRVL39ELzqCFWVqZ7RmIewDX9FGO+akcpPatXsWrq+83lvJL6l
ajxikoRIR8iHtA0CFy8VncG2XMkWZvpwI8dAvWglZYu3PZ9M3dt9W/mkRXBL5p+e
Lb9GzPCYA31gKcM7KJJjHD7nd5mmtfDxR604S+q0Mshw/fD4SDyC7VqmF9jTFPKm
xNrw6Or9clnZduafE1+UDFeOFT2VxXLjeu4W9T8abfHxluVFpX84X+Bit5jSoIcm
T8eeVR3TeSKsGw38LQj+T71sQ7JGb0yKDMtGPQr4bIoOPMgIlu+iA+OVwGX/EmqO
Mu13N+aEUwcnKOTtk339wzD9Wgfg99wKJY3mGEKX80US9BGAEXQ7wL15Pz6q3XzD
axt59WP6fApb2rz8GTvB4vxtc/F0KLVphkPuuvX4FxU6364QzP8Pkmex0xdLm5wU
b8Ab2eWfsCJjErNzXzIJ3zBHpd2Ru/fIc6S4XTfyMmczmsKpo7TzRCChtC5mFRzk
oVPUARW/ZcdNIp2vM7qipt312K8GC/8+a8sQSco5mGYYNBfRNgk=
=8ADW
-----END PGP SIGNATURE-----

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ