[DSA 6394-1] firefox-esr security update
Salvatore Bonaccorso <[email protected]> Wed, 22 Jul 2026 21:15:40 +0000
| Newsgroups | gmane.linux.debian.user.security.announce |
|---|---|
| Message-ID | <[email protected]> |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-6394-1 [email protected] https://www.debian.org/security/ Salvatore Bonaccorso July 22, 2026 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : firefox-esr CVE ID : CVE-2026-15718 CVE-2026-15719 CVE-2026-16349 CVE-2026-16350 CVE-2026-16351 CVE-2026-16352 CVE-2026-16353 CVE-2026-16354 CVE-2026-16355 CVE-2026-16356 CVE-2026-16357 CVE-2026-16358 CVE-2026-16359 CVE-2026-16360 CVE-2026-16361 CVE-2026-16362 CVE-2026-16363 CVE-2026-16368 CVE-2026-16369 CVE-2026-16371 CVE-2026-16374 CVE-2026-16375 CVE-2026-16377 CVE-2026-16379 CVE-2026-16381 CVE-2026-16383 CVE-2026-16387 CVE-2026-16390 CVE-2026-16391 CVE-2026-16396 CVE-2026-16405 CVE-2026-16412 Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code, bypass of the same-origin policy, privilege escalation, information disclosure, spoofing or sandbox escape. For the stable distribution (trixie), these problems have been fixed in version 140.13.0esr-1~deb13u1. We recommend that you upgrade your firefox-esr packages. For the detailed security status of firefox-esr please refer to its security tracker page at: https://security-tracker.debian.org/tracker/firefox-esr Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: [email protected] -----BEGIN PGP SIGNATURE----- iQKTBAEBCgB9FiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmphMalfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2 NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQACgkQBUy48xND z0SbzQ/8CsvoeNPZ6AosmtppNxMaPF0x0ZVn6VtIw6FUwlMfpfif1RT8StBs1ueu qwNl91nvy/rjBqPulx8dgB/TYmOJDJHp+DVaDiRaXWelYuvVNYHt5+EgWRXx059/ 0ZKDOc1XEmL6zhcSxxJET7NPjqVvSUXNEd1AMI2ZEpV1lBi3UHdyiObJ1AcN2P67 l47lPwAIZUldYncnM1eg9oVsJg6ydun8lCFhRv1nAwudwGNEmiXX2dkI1HIn1VBL jbL2T24KoS90IJ7tpTF1gfX/KLksH9vib5wY3bBod9WmVAlqSrdt3xWkFLdsWFGb cSX/PMW4NzpJ5np8n392vSSZnv0+ZjTiC0Ow6ZWlmcwzR7gsbeTamI6vS2AIz3xn 6VfSyljkfZsArCicLS6+XZ2CVkmnh0sa7T8lfEWr72WV5yIhRcM+Td4sleOtSJV3 HcpIKOHOZjyiUKZv/lz6YqHkYEvqNUjilAv6rRrhruOahEw7OvyctpWJzXgMzWWk MTrDLliK960pudbxHWpoL679OLMHHvF77WfVWt5iPX+1zU5z/moLze+7LDwPp5rE PbwKNa1Xnf29p90ZfEGPnWu7SAsBwUeGVMPBl4u9d6e1ZRr+c8pmCIol5vCmt09S cMyA/A3sRwJskUG0FvlKmA4VnlquzxJhLXg7pwXyfTORWOmZcmo= =eZIn -----END PGP SIGNATURE-----