[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index] [SECURITY] [DSA 6350-1] firefox-esr security update To: debian-security-announce@lists.debian.org Subject: [SECURITY] [DSA 6350-1] firefox-esr security update From: Moritz Muehlenhoff <jmm@debian.org> Date: Wed, 17 Jun 2026 18:01:48 +0000 Message-id: <[🔎] ajLhDPfvBtD_bzmT@seger.debian.org> Reply-to: debian-security-announce-request@lists.debian.org -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-6350-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff June 17, 2026 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : firefox-esr CVE ID : CVE-2026-12289 CVE-2026-12290 CVE-2026-12291 CVE-2026-12292 CVE-2026-12294 CVE-2026-12295 CVE-2026-12296 CVE-2026-12297 CVE-2026-12298 CVE-2026-12299 CVE-2026-12302 CVE-2026-12304 CVE-2026-12305 CVE-2026-12306 CVE-2026-12307 CVE-2026-12308 CVE-2026-12309 CVE-2026-12310 CVE-2026-12311 CVE-2026-12312 CVE-2026-12313 CVE-2026-12314 CVE-2026-12315 CVE-2026-12324 CVE-2026-12325 CVE-2026-12327 CVE-2026-12328 CVE-2026-12329 CVE-2026-12330 Multiple security issues have been found in the Mozilla Firefox web browser, which could potentially result in the execution of arbitrary code, bypass of the same-origin policy, privilege escalation, information disclosure, spoofing or sandbox escape. For the stable distribution (trixie), these problems have been fixed in version 140.12.0esr-1~deb13u1. We recommend that you upgrade your firefox-esr packages. For the detailed security status of firefox-esr please refer to its security tracker page at: https://security-tracker.debian.org/tracker/firefox-esr Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: debian-security-announce@lists.debian.org -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAmoy16AACgkQEMKTtsN8 TjayiQ/+JmolD0QkSMusXqa+UDPUy5ZakSYoV+r/J1hruDY1dsD43bWtyGm+Vq2/ 4uYcL8X1pv6XWVsh8rDV4mbl5Ew+fZP6gvEh3q/F4dH/xz8znXsgWPqs2VWhxjcx Pg/3qu591+SWufS3iO12N3njlhhRl2f9C5xOaaF5+q0zVbfRxDjdTsZmHY4hnD0w oRgYD+isCJ1ytKf44jVLcbQfm/mtgEmHWLTHeKp8aigjF40hR3EldCY1jONESjSa 5FKrPcV7QbvOTTsA8Uchg/9p983jPE9q5s8MBVuVu946vTk+McwVg3t5CcqM5OvT sF6U3mcHBirEIwwlculO1maNfLs9C+8QxEM27VgpA8JXDkCo2d1gVDbNG7DYKpip DGyux3dRJr9QIKmRkTAb+IlIXe1BUSJmpRZIPiBx6TE80nZnWYGX50oc+jGtZbEt X6x7mEzFckq8fD6vmz3Rqe7eZtfnGX2qOYfAoq4xrlIJscUCFGYusFR1fFysly6W Shkh5OjxeHESY082ybt/JlnWM+GP5ML0ZaPOjhcw33j4a83cFwJNp2rAbx5X+x4T B9T3+jEDx1/pzWEkc2/Z87hp0ui+YZIbicmxe4xacIkXNaakTJbQ7Ipm3y7BXQYK uvJSOJWNis3m8Hk17sAMLNQerNJT24w7NCwXH6cJK5jQHUFAv6Q= =7Ao3 -----END PGP SIGNATURE----- Reply to: debian-security-announce@lists.debian.org Moritz Muehlenhoff (on-list) Moritz Muehlenhoff (off-list) Prev by Date: [SECURITY] [DSA 6349-1] atril security update Previous by thread: [SECURITY] [DSA 6349-1] atril security update Index(es): Date Thread
A Debian security advisory details multiple vulnerabilities in Firefox ESR, including memory corruption flaws that could lead to arbitrary code execution, same-origin policy bypasses, privilege escalation, and sandbox escapes. The vulnerabilities affect the Debian stable distribution (trixie) and are addressed in firefox-esr version 140.12.0esr-1~deb13u1. Administrators are urged to upgrade their packages promptly to mitigate these risks.