Debian alert DSA-6178-1 (firefox-esr)
| From: | Salvatore Bonaccorso <carnil@debian.org> | |
| To: | debian-security-announce@lists.debian.org | |
| Subject: | [SECURITY] [DSA 6178-1] firefox-esr security update | |
| Date: | Wed, 25 Mar 2026 22:13:36 +0000 | |
| Message-ID: | <E1w5WTo-00000002798-2zto@seger.debian.org> |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-6178-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso March 25, 2026 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : firefox-esr CVE ID : CVE-2025-59375 CVE-2026-4684 CVE-2026-4685 CVE-2026-4686 CVE-2026-4687 CVE-2026-4688 CVE-2026-4689 CVE-2026-4690 CVE-2026-4691 CVE-2026-4692 CVE-2026-4693 CVE-2026-4694 CVE-2026-4695 CVE-2026-4696 CVE-2026-4697 CVE-2026-4698 CVE-2026-4699 CVE-2026-4700 CVE-2026-4701 CVE-2026-4702 CVE-2026-4704 CVE-2026-4705 CVE-2026-4706 CVE-2026-4707 CVE-2026-4708 CVE-2026-4709 CVE-2026-4710 CVE-2026-4713 CVE-2026-4714 CVE-2026-4715 CVE-2026-4716 CVE-2026-4717 CVE-2026-4718 CVE-2026-4719 CVE-2026-4720 CVE-2026-4721 Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code, sandbox escape, information disclosure, denial of service or privilege escalation. For the oldstable distribution (bookworm), these problems have been fixed in version 140.9.0esr-1~deb12u1. For the stable distribution (trixie), these problems have been fixed in version 140.9.0esr-1~deb13u1. We recommend that you upgrade your firefox-esr packages. For the detailed security status of firefox-esr please refer to its security tracker page at: https://security-tracker.debian.org/tracker/firefox-esr Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: debian-security-announce@lists.debian.org -----BEGIN PGP SIGNATURE----- iQKTBAEBCgB9FiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmnEV6VfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2 NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQACgkQBUy48xND z0QN0Q/6A5WCBDqDh8FyaiMSKluwq7lNrquoJcOCeOQJbP24XIXyq1nCDRAi2TRZ +Y3a3Dub1/yu5PZC40knteoOz28ez39KNINGtBfTksYvm9YDnvMTxynVw8LNfgfb bcoUrqCtqifa+N6jrpaMRLYkjY6T1jM9wOlZ2M9sMGY6j9yxmJ9S8mlH9pjdojVm jDSVu9IdwY1f15W4wmk7fxIMAZuxMuge8JYJ9uRRWtHoUXXDn0bIniBel9reVxW6 gmZJqP2kMwz4In9FYEzXRVdeuK2Shgwgiqxg47cYmPjQtwg1cv7gB43KnTRt5tTB krQ1WcVfn/cN4s67943O7zwkE/lYz26w/Bb22YKXx351rS1aM2VwBRRZVa1vavon tsUul/EzJCGRnaI27NEREmlLIalw0Lq7cfwDodcORCfBZ+VLN69IiRLMoXYfSAwO NTdSQum1+1l1DN7lFTAtlk23DHTUGjOGDW4D7tRHgIOdCw2JWAnSw9exgwW1q+pF TW9hAwJ+bzPRJsK6BIiT7DlxMvOEB4jHF3kzjazSjgjDHgAnEaUlzp5rqJZOiF+l v0GEl0T74weTyHMzogcZ6i9yNL6AQhdqIDXLMXi8xyWkjeLy3lJAUS4cqvB1tUeX MAfuJl1LPyGrTGmTguiZHn4+XGsPXKzwjFN3x6sPCiCm7xI1yc4= =YMR3 -----END PGP SIGNATURE-----
