Debian alert DLA-4439-1 (firefox-esr)
| From: | Emilio Pozuelo Monfort <pochu@debian.org> | |
| To: | <debian-lts-announce@lists.debian.org> | |
| Subject: | [SECURITY] [DLA 4439-1] firefox-esr security update | |
| Date: | Thu, 15 Jan 2026 19:39:34 +0100 | |
| Message-ID: | <20260115183934.0C02D5F00083@kamino> |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 - ------------------------------------------------------------------------- Debian LTS Advisory DLA-4439-1 debian-lts@lists.debian.org https://www.debian.org/lts/security/ Emilio Pozuelo Monfort January 15, 2026 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : firefox-esr Version : 140.7.0esr-1~deb11u1 CVE ID : CVE-2025-14327 CVE-2026-0877 CVE-2026-0878 CVE-2026-0879 CVE-2026-0880 CVE-2026-0882 CVE-2026-0883 CVE-2026-0884 CVE-2026-0885 CVE-2026-0886 CVE-2026-0887 CVE-2026-0890 CVE-2026-0891 Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code, sandbox escape, information disclosure or spoofing. For Debian 11 bullseye, these problems have been fixed in version 140.7.0esr-1~deb11u1. We recommend that you upgrade your firefox-esr packages. For the detailed security status of firefox-esr please refer to its security tracker page at: https://security-tracker.debian.org/tracker/firefox-esr Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEcJymx+vmJZxd92Q+nUbEiOQ2gwIFAmlpNGMACgkQnUbEiOQ2 gwKNXhAAx1PWbQptJEBaRFDjP5Dz6vVkhRWLj4PvG3JKMQgqWSoEsQnXnKfzuT/+ GpW8bCTY52PQXneyX6D/7zf/HCFHmgIKnbJKNvJCycX+B9VSBTGvf6WmIGmx/vyG btQYXCNnoN59Ei9AtbYL2Sxn+xwXLFzNU2zyKJDk1is+KKCITdzhCYXhnnQcm+LL B3ys7ORxNUYDLO0oFNrlDSnudw2vvH3fIXf1cgynO4YDeFvjqRE78yV6bHpVrOyi 6Nia1QjFUAyT5Tu57p6Y5EGQs3IY8JMfaU6xEkEVZSvmqqP0vww9Ny7jsdjA9hDF dm2/vobt0qoDerm8aixo6IhQZhvgTjS7e0NllXpjYa5e7nYIjj7HNc+8IFCKQ2b3 Bb2Mvqa4lwiL/Dw8pHs8FIPVRQ8XqswO4dPK5p8aid3hQMteJT5vtmGzYq1gwVTn mkR5m6qLTFXhEv+Ym9vymStbAnEpw/84VgbRhVboD6+M0X9gFhzDREU1F9psshVv 4AgxLZBT4XO7udreqbfdCJz1cljPORYdooYXQAhi452TE8/BN7PA73f7o3Tc4s1F xvzdHU7ywbj6eXVYQwx4eJ03ExlQIT7S20Gyq9T/8Vmr6R0+6eiMygyhCZlNwCbs uv0MhH9ONPdT/uKuFxPoiv5wyx00hFTBtwzpgWhxlGqBfWUuuzI= =Iyej -----END PGP SIGNATURE-----
