[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

[SECURITY] [DLA 4635-1] firefox-esr security update



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

- -------------------------------------------------------------------------
Debian LTS Advisory DLA-4635-1                debian-lts@lists.debian.org
https://www.debian.org/lts/security/               Emilio Pozuelo Monfort
June 19, 2026                                 https://wiki.debian.org/LTS
- -------------------------------------------------------------------------

Package        : firefox-esr
Version        : 140.12.0esr-1~deb11u1 140.12.0esr-1~deb12u1
CVE ID         : CVE-2026-12289 CVE-2026-12290 CVE-2026-12291 CVE-2026-12292
                 CVE-2026-12294 CVE-2026-12295 CVE-2026-12296 CVE-2026-12297
                 CVE-2026-12298 CVE-2026-12299 CVE-2026-12302 CVE-2026-12304
                 CVE-2026-12305 CVE-2026-12306 CVE-2026-12307 CVE-2026-12308
                 CVE-2026-12309 CVE-2026-12310 CVE-2026-12311 CVE-2026-12312
                 CVE-2026-12313 CVE-2026-12314 CVE-2026-12315 CVE-2026-12324
                 CVE-2026-12325 CVE-2026-12327 CVE-2026-12328 CVE-2026-12329
                 CVE-2026-12330

Multiple security issues have been found in the Mozilla Firefox web
browser, which could potentially result in the execution of arbitrary
code, bypass of the same-origin policy, privilege escalation,
information disclosure, spoofing or sandbox escape.

For Debian 11 bullseye, these problems have been fixed in version
140.12.0esr-1~deb11u1.

For Debian 12 bookworm, these problems have been fixed in version
140.12.0esr-1~deb12u1.

We recommend that you upgrade your firefox-esr packages.

For the detailed security status of firefox-esr please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/firefox-esr

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEEcJymx+vmJZxd92Q+nUbEiOQ2gwIFAmo1ARQACgkQnUbEiOQ2
gwJEFw//U1hesyS08goEd3d55iX7qnmBajnonBa+9qAFDXFVXEA1D9UvqSghrvDQ
CyEnI/CXygsXUQYI7sIeugHopC9qhf1+q71GbobZci2ZCr5ha4UdfJBWsGRSjYI5
5HQSYSDgMyVOI47WnDLpyB3TvbNMQLMUX0LEeSy5MjG6BbM79IoIHSJET5TbCSHn
kgMWN7d9SxjDyhjzed8TwCGlLGnctofywNC5fcF+/iiVi9BtjV3xBrZEkPwxGKZV
WQ7lzH3ixq2WAxznHeHudT7j+zn8HiR5hw0347R4hRaxpYXKfDOIVSGk4UcEEtqt
I4Dy5AA4FTOXXdr+cyPaIqgBU8+FLUkPvWqQOgygIVBbgwXjr6wunUQjVZVT88cf
Tb52M/ZdikAo9Qx119EJRuzDx2DCQVNrEEdlfgzBdo0eLzeYs01H0bL6KYvcAuAX
dx3IwjNmwidZLNdt8ImnHcL1nV61sOOHVOHxAJqD7n97c2PYVJfrmWSyn3bESqLR
dEUHBbAn6DvWbOm/fX+dibZ1We9KluCkGhpcLzlvzOuL5IQXDbTMiHYh5370/K0L
4lfsVOKiSfF1GgEYpWElIsA8NKDbmqnTC5LgHJNldZ4UYSMUX6o+BRlj9dQrmJUJ
dQPwevPcdp9ZmuDsEwoX1atN0wEQyvC2OssYnktlcgaGtd1/uS8=
=wm1O
-----END PGP SIGNATURE-----


Reply to: