-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
- -------------------------------------------------------------------------
Debian LTS Advisory DLA-4750-1 [email protected]
https://www.debian.org/lts/security/ Emilio Pozuelo Monfort
August 21, 2026 https://wiki.debian.org/LTS
- -------------------------------------------------------------------------
Package : firefox-esr
Version : 140.14.0esr-1~deb11u1 140.14.0esr-1~deb12u1
CVE ID : CVE-2026-74934 CVE-2026-74935 CVE-2026-74936 CVE-2026-74939
CVE-2026-74940 CVE-2026-74941 CVE-2026-74942 CVE-2026-74943
CVE-2026-74944 CVE-2026-74945 CVE-2026-74946 CVE-2026-74948
CVE-2026-74949 CVE-2026-74953 CVE-2026-74957 CVE-2026-74959
CVE-2026-74960 CVE-2026-74962 CVE-2026-74963 CVE-2026-74964
CVE-2026-74965 CVE-2026-74967 CVE-2026-74969 CVE-2026-74971
CVE-2026-74972 CVE-2026-74973 CVE-2026-74974 CVE-2026-74976
CVE-2026-74983 CVE-2026-74987 CVE-2026-74990
Multiple security issues have been found in the Mozilla Firefox web
browser, which could potentially result in the execution of arbitrary
code, privilege escalation, information disclosure or bypass of the
same-origin policy.
For Debian 11 bullseye, these problems have been fixed in version
140.14.0esr-1~deb11u1.
For Debian 12 bookworm, these problems have been fixed in version
140.14.0esr-1~deb12u1.
We recommend that you upgrade your firefox-esr packages.
For the detailed security status of firefox-esr please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/firefox-esr
Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCAAdFiEEcJymx+vmJZxd92Q+nUbEiOQ2gwIFAmqIaUMACgkQnUbEiOQ2
gwLmLw/9Fk2ha3nrZ8uRTx0IYQpV1bGe6gbFlNXl8RavgbsLMmHuxjSIeeWUruUR
iTVK3jXtkZ36Otkk3gsmQxbOuM2lYqa+aW9efJoeIU2M2HgeqXsoMYaEHYYb/NLh
vkxfSuSQ9T4pNS7I5Wde/EMPiCWGaakKZQX2bjoeShmECRK7YKQHd7ViLkhCZYZ0
uHp0YhWViwE+st/vdRpXYSjHVXjcaaqSw1OpXfg/Ofhkb4kynpJQYMgY4smgeMSP
iSPNV32RIJs/pCV65sPuZjFZXZ4R6E2QCjpzS3luPpXMwMO5wwHeqHZ0RliWGmrw
VoLUoJ1iqCut2naAGzBz/9vCg7dwaKTLt1fYxiusawYEcd4dUBEEy3LQjgJv+Wt9
r8CKOtfAaGrYYwvugLz7rGqEqP8/NDafkHm2eWQEjDqxkyEkHSQO24Ug6bfW9Kl9
4j6KTYt0peYLrnHesV6mUD7kT7ckBzF3NLTwA/ZQWqyn8pZA/iXkJFLP7gSaAR1D
bK/uKvmyaULoiJskv45Oknq9uGBZwpmRXBbmDbKjOFKrxs7Pk1Rk9nC1xRZZTD7f
SgP6jm05VT00lyFoCtrTpanEMi5TreJ7OtDYyaeCG6c8/F7B87rRZuYdW6YqNoDC
U5xLTGwn0XrgNj/fbZzegD3+FvQG/vrNT9T16xH5JTimfKus/Us=
=Z+Re
-----END PGP SIGNATURE-----