Debian alert DLA-2093-1 (firefox-esr)
From: | Emilio Pozuelo Monfort <pochu@debian.org> | |
To: | debian-lts-announce@lists.debian.org | |
Subject: | [SECURITY] [DLA 2093-1] firefox-esr security update | |
Date: | Sat, 1 Feb 2020 05:15:49 +0100 | |
Message-ID: | <25e6ae33-f7f9-4fa3-956f-f92229d5c736@debian.org> |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Package : firefox-esr Version : 68.4.1esr-1~deb8u1 CVE ID : CVE-2019-17026 An issue was found in the IonMonkey JIT compiler of the Mozilla Firefox web browser which could lead to arbitrary code execution. For Debian 8 "Jessie", this problem has been fixed in version 68.4.1esr-1~deb8u1. We recommend that you upgrade your firefox-esr packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEcJymx+vmJZxd92Q+nUbEiOQ2gwIFAl40+3IACgkQnUbEiOQ2 gwJPDg//RYUr2MqUQyHkSA1blir2bcv3+9il7z7j/htwxlduNpHTkhNqU1bKo+Oz TntJvUM293ld25ctKl/rUQzyxk8ps71zXaws6ipVcC6Rd72CsN3+CP22rApdj38S NdhseOPtQnrfDxONujbeke8IGkiYLvSXPkHnbwSO7k5gV69/F/gAjNsMlIih5ia1 wo8jOncmGx057a8FQSWin6zooZ3Rab/ezHIgrj9KYRWH7mEsOvThQsNIJPlxgccb MSs7uGCaqzGXpB+Ay6NlO4Ockfew0RxWCnItsa5a23JHSkUWZpc0nzJgZHUBa4vN 1DwLMdxVIoa0S7mIYn3amRnpr55oscKyDUkQF+DHjsYSK/y6DIFGVHt1yn0bLlWV 0NAQjaGiDoVO/t2mLSu+FMIK3QEsW+Eya5Z+OJF0ocpRjs082slVI0oFo5H5Hc6P +Smolv7ycmMM37ByOx2IwSZR0i9kQ9z4IUBC+wRtthpHMdLWdXZ82uKBMW477jZB fL7S6FKEMGuP6GT065px+vuANQHnfZUem6P0Rhykg/xZoX3J20e6ILFoxV5hXZnW unXPgG9ERGHOhBgq/wLSxAVvNBEsyPitNwLv0wl+i2GIS9rZYMY/srUycWf6Q7Yz 0777ihDhmvj9+mB8CukUfOnsslkHGh2cREAJopftV7hHKxqFdp8= =O7i1 -----END PGP SIGNATURE-----