Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
c1516610 by Salvatore Bonaccorso at 2023-10-25T07:49:06+02:00
Track fixes for CVEs for firefox-esr via unstable

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -125,14 +125,14 @@ CVE-2023-39619 (ReDos in NPMJS Node Email Check v.1.0.4 
allows an attacker to ca
 CVE-2023-39231 (PingFederate using the PingOne MFA adapter allows a new MFA 
device to  ...)
        NOT-FOR-US: PingFederate
 CVE-2023-5732 (An attacker could have created a malicious link using 
bidirectional ch ...)
-       - firefox-esr <unfixed>
+       - firefox-esr 115.4.0esr-1
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2023-46/#CVE-2023-5732
 CVE-2023-5731 (Memory safety bugs present in Firefox 118. Some of these bugs 
showed e ...)
        - firefox <unfixed>
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2023-45/#CVE-2023-5731
 CVE-2023-5730 (Memory safety bugs present in Firefox 118, Firefox ESR 115.3, 
and Thun ...)
        - firefox <unfixed>
-       - firefox-esr <unfixed>
+       - firefox-esr 115.4.0esr-1
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2023-45/#CVE-2023-5730
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2023-46/#CVE-2023-5730
 CVE-2023-5729 (A malicious web site can enter fullscreen mode while 
simultaneously tr ...)
@@ -140,7 +140,7 @@ CVE-2023-5729 (A malicious web site can enter fullscreen 
mode while simultaneous
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2023-45/#CVE-2023-5729
 CVE-2023-5728 (During garbage collection extra operations were performed on a 
object  ...)
        - firefox <unfixed>
-       - firefox-esr <unfixed>
+       - firefox-esr 115.4.0esr-1
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2023-45/#CVE-2023-5728
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2023-46/#CVE-2023-5728
 CVE-2023-5727 (The executable file warning was not presented when downloading 
.msix,  ...)
@@ -155,12 +155,12 @@ CVE-2023-5726 (A website could have obscured the full 
screen notification by usi
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2023-46/#CVE-2023-5726
 CVE-2023-5725 (A malicious installed WebExtension could open arbitrary URLs, 
which un ...)
        - firefox <unfixed>
-       - firefox-esr <unfixed>
+       - firefox-esr 115.4.0esr-1
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2023-45/#CVE-2023-5725
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2023-46/#CVE-2023-5725
 CVE-2023-5724 (Drivers are not always robust to extremely large draw calls and 
in som ...)
        - firefox <unfixed>
-       - firefox-esr <unfixed>
+       - firefox-esr 115.4.0esr-1
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2023-45/#CVE-2023-5724
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2023-46/#CVE-2023-5724
 CVE-2023-5723 (An attacker with temporary script access to a site could have 
set a co ...)
@@ -171,7 +171,7 @@ CVE-2023-5722 (Using iterative requests an attacker was 
able to learn the size o
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2023-45/#CVE-2023-5722
 CVE-2023-5721 (It was possible for certain browser prompts and dialogs to be 
activate ...)
        - firefox <unfixed>
-       - firefox-esr <unfixed>
+       - firefox-esr 115.4.0esr-1
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2023-45/#CVE-2023-5721
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2023-46/#CVE-2023-5721
 CVE-2023-5746 (A vulnerability regarding use of externally-controlled format 
string i ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c15166104248e622013f9b746f5701a5c4dd32b5

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c15166104248e622013f9b746f5701a5c4dd32b5
You're receiving this email because of your account on salsa.debian.org.


_______________________________________________
debian-security-tracker-commits mailing list
debian-security-tracker-commits@alioth-lists.debian.net
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to