[DSA 6003-1] firefox-esr security update
Moritz Muehlenhoff <[email protected]>
| Newsgroups | gmane.linux.debian.user.security.announce |
|---|---|
| Message-ID | <[email protected]> |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-6003-1 [email protected] https://www.debian.org/security/ Moritz Muehlenhoff September 18, 2025 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : firefox-esr CVE ID : CVE-2025-10527 CVE-2025-10528 CVE-2025-10529 CVE-2025-10532 CVE-2025-10533 CVE-2025-10536 CVE-2025-10537 Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code, sandbox escape, information disclosure or bypass of the same-origin policy. Debian follows the extended support releases (ESR) of Firefox. So starting with this update we're now following the 140.x releases. Between 128.x and 140.x, Firefox has seen a number of feature updates. For more information please refer to https://www.firefox.com/en-US/firefox/140.0esr/releasenotes/ For the oldstable distribution (bookworm), these problems have been fixed in version 140.3.0esr-1~deb12u1. For the stable distribution (trixie), these problems have been fixed in version 140.3.0esr-1~deb13u1. We recommend that you upgrade your firefox-esr packages. For the detailed security status of firefox-esr please refer to its security tracker page at: https://security-tracker.debian.org/tracker/firefox-esr Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: [email protected] -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAmjMUrwACgkQEMKTtsN8 TjbgSw/+LroTP1zAPU4yibzrwqEtXV/WPx0D+U4MyVGCflDvSwbEne8g0w3Y0oxY xHnZOHHu61Tw2U5dywBLgbqo/Z4ylKhv+RRqa4IlXgmzXD8rkNq110w7runm+Ih9 pokL5rdSr040rOTnlgcoevACxaqixcfqQHKrTOFzSPbJI+QG5uCzN7tER3oh0e0a nx2u/tt+AXErBJsxJ3Gz80tcxfmyT/SLGjD13XyuXCJ5RycULT6DIqt/61P3uRys T2f4wTppZvg89DoZErhQp0a14q5LEgplkjy+hVFuQQtI6Ez6hQE9RCb4a/EDa8Tc K7El2YwJU9xoqGhXuCqzcIeF9qBNmo2dioNM5KPuXPpcgXQESCBV0pU/D2Y79T5j x/W6/rJnWtxNjX7l9ap7w3NuyfU1H1mrdr8QeF0n2WnzQOgea/6fEu5nL8y4J3G9 Mmpi0ofvkhoLZCfqlzKAvlkZU8c4iicfznniJJ4+VMQl5Ivb3DWoDKI9g1MS95jR SaxHQa/eEfeYcqzAf4FKWC4MuEnGgmDff5C/pSBB0Gh8FCadJCJ5CpxZ8I3QhlB9 Uu3WWznY9fLIBsmltqTE0jjbFqkiCyCM5HuuWiRpGzXGjJrpt+1L46W96jgbaOtN H/E6a0988z3bvLahlTJex44GEjA1+lahjJRf65xv6vg8TGiW4Vs= =oCM9 -----END PGP SIGNATURE-----