[Git][security-tracker-team/security-tracker][master] new firefox-esr issues
Moritz Muehlenhoff
jmm at debian.org
Tue Jan 26 14:40:32 GMT 2021
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
9b89e884 by Moritz Muehlenhoff at 2021-01-26T15:39:33+01:00
new firefox-esr issues
- - - - -
2 changed files:
- data/CVE/list
- data/dsa-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -5139,6 +5139,8 @@ CVE-2021-23965
RESERVED
CVE-2021-23964
RESERVED
+ - firefox-esr <unfixed>
+ NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2021-04/#CVE-2021-23964
CVE-2021-23963
RESERVED
CVE-2021-23962
@@ -5147,6 +5149,8 @@ CVE-2021-23961
RESERVED
CVE-2021-23960
RESERVED
+ - firefox-esr <unfixed>
+ NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2021-04/#CVE-2021-23960
CVE-2021-23959
RESERVED
CVE-2021-23958
@@ -5159,8 +5163,12 @@ CVE-2021-23955
RESERVED
CVE-2021-23954
RESERVED
+ - firefox-esr <unfixed>
+ NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2021-04/#CVE-2021-23954
CVE-2021-23953
RESERVED
+ - firefox-esr <unfixed>
+ NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2021-04/#CVE-2021-23953
CVE-2021-23952
RESERVED
CVE-2021-23951
@@ -27122,6 +27130,8 @@ CVE-2020-26977 (By attempting to connect a website using an unresponsive port, a
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2020-54/#CVE-2020-26977
CVE-2020-26976 (When a HTTPS pages was embedded in a HTTP page, and there was a servic ...)
- firefox 84.0-1
+ - firefox-esr <unfixed>
+ NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2021-04/#CVE-2020-26976
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2020-54/#CVE-2020-26976
CVE-2020-26975 (When a malicious application installed on the user's device broadcast ...)
- firefox <not-affected> (Android specific)
@@ -50276,7 +50286,6 @@ CVE-2020-16044
- firefox 84.0.2-1
- firefox-esr 78.6.1esr-1
- thunderbird 1:78.6.1-1
- [buster] - thunderbird <postponed> (Minor issue, wait until next Mozilla security cycle)
[stretch] - thunderbird <postponed> (Minor issue, wait until next Mozilla security cycle)
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2021-01/#CVE-2020-16044
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2021-02/#CVE-2020-16044
=====================================
data/dsa-needed.txt
=====================================
@@ -19,6 +19,8 @@ chromium
dnsmasq (seb)
Maintainer/Upstream worked on patches
--
+firefox-esr (jmm)
+--
knot-resolver
Santiago Ruano Rincón proposed a debdiff for review
--
@@ -35,6 +37,8 @@ python-pysaml2
--
slurm-llnl (jmm)
--
+thunderbird (jmm)
+--
xcftools
Hugo proposed to work on this update
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/9b89e884c0fe77cd42e323ece71c90e4ad09b4e2
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/9b89e884c0fe77cd42e323ece71c90e4ad09b4e2
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20210126/1a804460/attachment.html>
More information about the debian-security-tracker-commits
mailing list