Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits: 8ff7a103 by Salvatore Bonaccorso at 2024-01-24T07:47:23+01:00 Track fixed version for firefox-esr via unstable - - - - - 1 changed file: - data/CVE/list Changes: ===================================== data/CVE/list ===================================== @@ -135,7 +135,7 @@ CVE-2023-42143 (Missing Integrity Check in Shelly TRV 20220811-152343/v2.1.8@5af NOT-FOR-US: Shelly CVE-2024-0755 (Memory safety bugs present in Firefox 121, Firefox ESR 115.6, and Thun ...) - firefox 122.0-1 - - firefox-esr <unfixed> + - firefox-esr 115.7.0esr-1 - thunderbird 1:115.7.0-1 NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2024-01/#CVE-2024-0755 NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2024-02/#CVE-2024-0755 @@ -145,7 +145,7 @@ CVE-2024-0754 (Some WASM source files could have caused a crash when loaded in d NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2024-01/#CVE-2024-0754 CVE-2024-0753 (In specific HSTS configurations an attacker could have bypassed HSTS o ...) - firefox 122.0-1 - - firefox-esr <unfixed> + - firefox-esr 115.7.0esr-1 - thunderbird 1:115.7.0-1 NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2024-01/#CVE-2024-0753 NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2024-02/#CVE-2024-0753 @@ -155,21 +155,21 @@ CVE-2024-0752 (A use-after-free crash could have occurred on macOS if a Firefox NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2024-01/#CVE-2024-0752 CVE-2024-0751 (A malicious devtools extension could have been used to escalate privil ...) - firefox 122.0-1 - - firefox-esr <unfixed> + - firefox-esr 115.7.0esr-1 - thunderbird 1:115.7.0-1 NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2024-01/#CVE-2024-0751 NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2024-02/#CVE-2024-0751 NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2024-04/#CVE-2024-0751 CVE-2024-0750 (A bug in popup notifications delay calculation could have made it poss ...) - firefox 122.0-1 - - firefox-esr <unfixed> + - firefox-esr 115.7.0esr-1 - thunderbird 1:115.7.0-1 NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2024-01/#CVE-2024-0750 NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2024-02/#CVE-2024-0750 NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2024-04/#CVE-2024-0750 CVE-2024-0749 (A phishing site could have repurposed an `about:` dialog to show phish ...) - firefox 122.0-1 - - firefox-esr <unfixed> + - firefox-esr 115.7.0esr-1 - thunderbird 1:115.7.0-1 NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2024-01/#CVE-2024-0749 NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2024-02/#CVE-2024-0749 @@ -179,14 +179,14 @@ CVE-2024-0748 (A compromised content process could have updated the document URI NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2024-01/#CVE-2024-0748 CVE-2024-0747 (When a parent page loaded a child in an iframe with `unsafe-inline`, t ...) - firefox 122.0-1 - - firefox-esr <unfixed> + - firefox-esr 115.7.0esr-1 - thunderbird 1:115.7.0-1 NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2024-01/#CVE-2024-0747 NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2024-02/#CVE-2024-0747 NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2024-04/#CVE-2024-0747 CVE-2024-0746 (A Linux user opening the print preview dialog could have caused the br ...) - firefox 122.0-1 - - firefox-esr <unfixed> + - firefox-esr 115.7.0esr-1 - thunderbird 1:115.7.0-1 NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2024-01/#CVE-2024-0746 NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2024-02/#CVE-2024-0746 @@ -203,14 +203,14 @@ CVE-2024-0743 (An unchecked return value in TLS handshake code could have caused TODO: check src:nss CVE-2024-0742 (It was possible for certain browser prompts and dialogs to be activate ...) - firefox 122.0-1 - - firefox-esr <unfixed> + - firefox-esr 115.7.0esr-1 - thunderbird 1:115.7.0-1 NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2024-01/#CVE-2024-0742 NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2024-02/#CVE-2024-0742 NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2024-04/#CVE-2024-0742 CVE-2024-0741 (An out of bounds write in ANGLE could have allowed an attacker to corr ...) - firefox 122.0-1 - - firefox-esr <unfixed> + - firefox-esr 115.7.0esr-1 - thunderbird 1:115.7.0-1 NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2024-01/#CVE-2024-0741 NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2024-02/#CVE-2024-0741 View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8ff7a10367793c6ffb3dca2123e7223caea88eaa -- View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8ff7a10367793c6ffb3dca2123e7223caea88eaa You're receiving this email because of your account on salsa.debian.org.
_______________________________________________ debian-security-tracker-commits mailing list debian-security-tracker-commits@alioth-lists.debian.net https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits