[Git][security-tracker-team/security-tracker][master] Track fixes for CVEs for firefox-esr via unstable

Salvatore Bonaccorso (@carnil) carnil at debian.org
Wed Oct 25 06:49:40 BST 2023



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
c1516610 by Salvatore Bonaccorso at 2023-10-25T07:49:06+02:00
Track fixes for CVEs for firefox-esr via unstable

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -125,14 +125,14 @@ CVE-2023-39619 (ReDos in NPMJS Node Email Check v.1.0.4 allows an attacker to ca
 CVE-2023-39231 (PingFederate using the PingOne MFA adapter allows a new MFA device to  ...)
 	NOT-FOR-US: PingFederate
 CVE-2023-5732 (An attacker could have created a malicious link using bidirectional ch ...)
-	- firefox-esr <unfixed>
+	- firefox-esr 115.4.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2023-46/#CVE-2023-5732
 CVE-2023-5731 (Memory safety bugs present in Firefox 118. Some of these bugs showed e ...)
 	- firefox <unfixed>
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2023-45/#CVE-2023-5731
 CVE-2023-5730 (Memory safety bugs present in Firefox 118, Firefox ESR 115.3, and Thun ...)
 	- firefox <unfixed>
-	- firefox-esr <unfixed>
+	- firefox-esr 115.4.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2023-45/#CVE-2023-5730
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2023-46/#CVE-2023-5730
 CVE-2023-5729 (A malicious web site can enter fullscreen mode while simultaneously tr ...)
@@ -140,7 +140,7 @@ CVE-2023-5729 (A malicious web site can enter fullscreen mode while simultaneous
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2023-45/#CVE-2023-5729
 CVE-2023-5728 (During garbage collection extra operations were performed on a object  ...)
 	- firefox <unfixed>
-	- firefox-esr <unfixed>
+	- firefox-esr 115.4.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2023-45/#CVE-2023-5728
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2023-46/#CVE-2023-5728
 CVE-2023-5727 (The executable file warning was not presented when downloading .msix,  ...)
@@ -155,12 +155,12 @@ CVE-2023-5726 (A website could have obscured the full screen notification by usi
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2023-46/#CVE-2023-5726
 CVE-2023-5725 (A malicious installed WebExtension could open arbitrary URLs, which un ...)
 	- firefox <unfixed>
-	- firefox-esr <unfixed>
+	- firefox-esr 115.4.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2023-45/#CVE-2023-5725
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2023-46/#CVE-2023-5725
 CVE-2023-5724 (Drivers are not always robust to extremely large draw calls and in som ...)
 	- firefox <unfixed>
-	- firefox-esr <unfixed>
+	- firefox-esr 115.4.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2023-45/#CVE-2023-5724
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2023-46/#CVE-2023-5724
 CVE-2023-5723 (An attacker with temporary script access to a site could have set a co ...)
@@ -171,7 +171,7 @@ CVE-2023-5722 (Using iterative requests an attacker was able to learn the size o
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2023-45/#CVE-2023-5722
 CVE-2023-5721 (It was possible for certain browser prompts and dialogs to be activate ...)
 	- firefox <unfixed>
-	- firefox-esr <unfixed>
+	- firefox-esr 115.4.0esr-1
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2023-45/#CVE-2023-5721
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2023-46/#CVE-2023-5721
 CVE-2023-5746 (A vulnerability regarding use of externally-controlled format string i ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c15166104248e622013f9b746f5701a5c4dd32b5

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c15166104248e622013f9b746f5701a5c4dd32b5
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20231025/04999aff/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list