New Debian firefox-esr 128.6.0esr-1~deb12u1 fixes: This update addresses the following issues: * firefox: thunderbird: WebChannel APIs susceptible to confused deputy attack (CVE-2025-0237) * firefox: thunderbird: Use-after-free when breaking lines in text (CVE-2025-0238) * firefox: Alt-Svc ALPN validation failure when redirected (CVE-2025-0239) * firefox: Compartment mismatch when parsing JavaScript JSON module (CVE-2025-0240) * firefox: Memory corruption when using JavaScript Text Segmentation (CVE-2025-0241) * firefox: thunderbird: Memory safety bugs fixed in Firefox 134, Thunderbird 134, Firefox ESR 115.19, Firefox ESR 128.6, Thunderbird 115.19, and Thunderbird 128.6 (CVE-2025-0242) * firefox: thunderbird: Memory safety bugs fixed in Firefox 134, Thunderbird 134, Firefox ESR 128.6, and Thunderbird 128.6 (CVE-2025-0243)
--- mirror/ftp/pool/main/f/firefox-esr/firefox-esr_128.5.0esr-1~deb12u1.dsc +++ apt/ucs_5.2-0-errata5.2-0/source/firefox-esr_128.6.0esr-1~deb12u1.dsc @@ -1,3 +1,10 @@ +128.6.0esr-1~deb12u1 [Wed, 08 Jan 2025 05:45:21 +0900] Mike Hommey <glandium@debian.org>: + + * New upstream release. + * Fixes for mfsa2025-02, also known as: + CVE-2025-0237, CVE-2025-0238, CVE-2025-0239, CVE-2025-0240, + CVE-2025-0241, CVE-2025-0242, CVE-2025-0243. + 128.5.0esr-1~deb12u1 [Wed, 27 Nov 2024 09:12:42 +0900] Mike Hommey <glandium@debian.org>: * New upstream release. <http://piuparts.knut.univention.de/5.2-0/#4481713865669382649>
OK: bug OK: yaml OK: announce_errata OK: patch OK: piuparts [5.2-0] 96952af8c4 Bug #57919: firefox-esr 128.6.0esr-1~deb12u1 doc/errata/staging/firefox-esr.yaml | 27 +++++++++++++++++++++++++++ 1 file changed, 27 insertions(+)
<https://errata.software-univention.de/#/?erratum=5.2x4>