Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits: 276424ff by Salvatore Bonaccorso at 2025-04-02T08:35:14+02:00 Track fixed version for firefox via unstable upload - - - - - 1 changed file: - data/CVE/list Changes: ===================================== data/CVE/list ===================================== @@ -755,10 +755,10 @@ CVE-2025-21894 (In the Linux kernel, the following vulnerability has been resolv - linux 6.12.19-1 NOTE: https://git.kernel.org/linus/a562d0c4a893eae3ea51d512c4d90ab858a6b7ec (6.14-rc5) CVE-2025-3034 (Memory safety bugs present in Firefox 136 and Thunderbird 136. Some of ...) - - firefox <unfixed> + - firefox 137.0-1 NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2025-20/#CVE-2025-3034 CVE-2025-3030 (Memory safety bugs present in Firefox 136, Thunderbird 136, Firefox ES ...) - - firefox <unfixed> + - firefox 137.0-1 - firefox-esr 128.9.0esr-1 - thunderbird <unfixed> NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2025-20/#CVE-2025-3030 @@ -768,23 +768,23 @@ CVE-2025-3033 (After selecting a malicious Windows `.url` shortcut from the loca - firefox <not-affected> (Only affects Firefox on Windows) NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2025-20/#CVE-2025-3033 CVE-2025-3035 (By first using the AI chatbot in one tab and later activating it in an ...) - - firefox <unfixed> + - firefox 137.0-1 NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2025-20/#CVE-2025-3035 CVE-2025-3029 (A crafted URL containing specific Unicode characters could have hidden ...) - - firefox <unfixed> + - firefox 137.0-1 - firefox-esr 128.9.0esr-1 - thunderbird <unfixed> NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2025-20/#CVE-2025-3029 NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2025-22/#CVE-2025-3029 NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2025-24/#CVE-2025-3029 CVE-2025-3032 (Leaking of file descriptors from the fork server to web content proces ...) - - firefox <unfixed> + - firefox 137.0-1 NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2025-20/#CVE-2025-3032 CVE-2025-3031 (An attacker could read 32 bits of values spilled onto the stack in a J ...) - - firefox <unfixed> + - firefox 137.0-1 NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2025-20/#CVE-2025-3031 CVE-2025-3028 (JavaScript code running while transforming a document with the XSLTPro ...) - - firefox <unfixed> + - firefox 137.0-1 - firefox-esr 128.9.0esr-1 - thunderbird <unfixed> NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2025-20/#CVE-2025-3028 View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/276424ff30ba75c5fbaa8f906d5a6e0d96f395bf -- View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/276424ff30ba75c5fbaa8f906d5a6e0d96f395bf You're receiving this email because of your account on salsa.debian.org.
_______________________________________________ debian-security-tracker-commits mailing list debian-security-tracker-commits@alioth-lists.debian.net https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits