New Debian firefox-esr 78.10.0esr-1~deb9u1 fixes: This update addresses the following issues: * More internal network hosts could have been probed by a malicious webpage (CVE-2021-23961) * Out of bound write due to lazy initialization (CVE-2021-23994) * Use-after-free in Responsive Design Mode (CVE-2021-23995) * Secure Lock icon could have been spoofed (CVE-2021-23998) * Blob URLs may have been granted additional privileges (CVE-2021-23999) * Arbitrary FTP command execution on FTP servers using an encoded URL (CVE-2021-24002) * Incorrect size computation in WebAssembly JIT could lead to null-reads (CVE-2021-29945) * Port blocking could be bypassed (CVE-2021-29946)
--- mirror/ftp/4.4/unmaintained/4.4-8/source/firefox-esr_78.9.0esr-1~deb9u1.dsc +++ apt/ucs_4.4-0-errata4.4-8/source/firefox-esr_78.10.0esr-1~deb9u1.dsc @@ -1,3 +1,14 @@ +78.10.0esr-1~deb9u1 [Wed, 21 Apr 2021 23:29:18 +0200] Emilio Pozuelo Monfort <pochu@debian.org>: + + * Backport to stretch. + +78.10.0esr-1 [Tue, 20 Apr 2021 06:36:15 +0900] Mike Hommey <glandium@debian.org>: + + * New upstream release. + * Fixes for mfsa2021-15, also known as: + CVE-2021-23994, CVE-2021-23995, CVE-2021-23998, CVE-2021-23961, + CVE-2021-23999, CVE-2021-24002, CVE-2021-29945, CVE-2021-29946. + 78.9.0esr-1~deb9u1 [Wed, 24 Mar 2021 10:52:26 +0100] Emilio Pozuelo Monfort <pochu@debian.org>: * Backport to stretch. <http://piuparts.knut.univention.de/4.4-8/#893705986867535109>
OK: yaml OK: announce_errata OK: patch OK: piuparts [4.4-8] 67febeaa7d Bug #53153: firefox-esr 78.10.0esr-1~deb9u1 doc/errata/staging/firefox-esr.yaml | 29 +++++++++++++++++++++++++++++ 1 file changed, 29 insertions(+)
<https://errata.software-univention.de/#/?erratum=4.4x963>