-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-4600-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff January 09, 2020 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : firefox-esr CVE ID : CVE-2019-17026 CVE-2019-17024 CVE-2019-17022 CVE-2019-17017 CVE-2019-17016 Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code, data exfiltration or cross-site scripting. For the oldstable distribution (stretch), this problem has been fixed in version 68.4.1esr-1~deb9u1. For the stable distribution (buster), this problem has been fixed in version 68.4.1esr-1~deb10u1. We recommend that you upgrade your firefox-esr packages. For the detailed security status of firefox-esr please refer to its security tracker page at: https://security-tracker.debian.org/tracker/firefox-esr Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: debian-security-announce@lists.debian.org -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAl4W7/gACgkQEMKTtsN8 Tja0+xAAhYxlP14LJHm+kdJRLiL/+AMGaNsofWF5DtCYtNYQbd2rrp2bqlj/Sa9E agkLMLFRUliDx91AM3tFahoN6ZS9tGAEc4/qAR5rldyElXFPiTZWm0S+1SwO0Hob tLuzYyLFECMEH7K66wo8ZJxI1zfyfViluOAo+P/AtfEioyfbq+fvc66DMUlCSFiR oAVPQnsCEO/i64uvSu7PxJ2ZrZePVwwgkivpeNcjpjPI7ooWpKJgs6tIZadTp1ic YamBUqI+kjU+1NEV9ss99AtDYOfQE+nCZ8YkOP60CofQefFdygmimGN9gwLc4Uy0 U8biLH+M5E/NT50MHTjv/N+eM42eR5A1BWZBjqqttlBCoKLlV5gRx7Rfkgh5FUaO AEPs4sDChqRzYLO/LVEpUHC/C+HrFOQhqNtea+4IlzepQZbWOAZU8VsOSkMQLCOI rvenKY0O5cTTBC8sVkfOJ42Ri+fI1KRe6MJaPtvw2ghj13yRr1cx+427u7uT5+Lp wjUgH5isdk8L3L/t37a93TNXe0YgkQc13gzkZR1w7kQ+TumgRjarlZ5wgwiwiLPs IFStyCEg+RjQqX00hL3+cs3onQeTPSeElYxAGytEa2xneOpR8h7WJXm8CJGRy/V+ wfozphRdqUjP7V8+SewKYdyFGk7mpFNLbm4bnaQvstpIOdxSrDA=L9xt -----END PGP SIGNATURE-----