|
|
Subscribe / Log in / New account

Debian alert DSA-6025-1 (firefox-esr)

From:  Moritz Muehlenhoff <jmm@debian.org>
To:  debian-security-announce@lists.debian.org
Subject:  [SECURITY] [DSA 6025-1] firefox-esr security update
Date:  Wed, 15 Oct 2025 21:09:23 +0000
Message-ID:  <aPANg6s2hcJAY0iD@seger.debian.org>

-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-6025-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff October 15, 2025 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : firefox-esr CVE ID : CVE-2025-11708 CVE-2025-11709 CVE-2025-11710 CVE-2025-11711 CVE-2025-11712 CVE-2025-11714 CVE-2025-11715 Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code, memory disclosure or cross-site scripting. For the oldstable distribution (bookworm), these problems have been fixed in version 140.4.0esr-1~deb12u1. For the stable distribution (trixie), these problems have been fixed in version 140.4.0esr-1~deb13u1. We recommend that you upgrade your firefox-esr packages. For the detailed security status of firefox-esr please refer to its security tracker page at: https://security-tracker.debian.org/tracker/firefox-esr Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: debian-security-announce@lists.debian.org -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAmjwBmgACgkQEMKTtsN8 TjaFRw/9E0mvdUXL2O0wWpYMZoq8im8IIKbOVN6t0ic3Cvi56XgI3x/6jo7klBAi AtmMVkHpCzB4fzpvLzFJ+hVvhCziSTLVKFzbZItSdVAnAlu5ihzniB/tqn9An6db AQZrOqzDfCcuPsLy4JxxT/GK7kdqG/vbknxdcDWaIWxxek8DMpCtLACwftzf0GoH zMFn2QocrgU8jNblTcrOsDoquwQfHw0N5l9LTrqi4wboBoBI8cw5H7rYOecnLHST ClLRbaHMrgmeHpyN43hjcMpK0aGUrZZacfHdZTe4wAxaFTDjeGQomaWV6j11DWnT L4VxlmDkOBb14v2I4oyvS302ZqrQfdtV8OUyAB4H5bqmb6mocrtpyy5O9/c5Y/PF NX2gK37zm/sVoB1sfLcYSevudq5z0Uzax6oG9XPBajisB2pEBfWphhx8ZwoQN0Kc X1JVOftHCxSwBLimhl3BU9MPKVC0vGDWVzcStaae2SXbB/m4kdQhn3DBY3LLeQ7F pXjBCeufn568K5pk76hmtrF2DAR4coyzQRxzuvNpX2/2aIBo3RVUBe7FyQNCpSiG oJLDS4egU6YrcYkXK6JtOnAlwRlBMBXeetrJJ4Iz4zZE7nsDkMTybaQi9/6ySs14 dYvY7+okj/aHkg5eu9Nfomyj2ciW17W3T5sIoyLUIb4vJh+3c/0= =RGa9 -----END PGP SIGNATURE-----


to post comments


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds