-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

===========================================================================
             AUSCERT External Security Bulletin Redistribution

                               ESB-2021.1949
                        firefox-esr security update
                                4 June 2021

===========================================================================

        AusCERT Security Bulletin Summary
        ---------------------------------

Product:           firefox-esr
Publisher:         Debian
Operating System:  Debian GNU/Linux
Impact/Access:     Execute Arbitrary Code/Commands -- Remote with User Interaction
                   Denial of Service               -- Remote with User Interaction
Resolution:        Patch/Upgrade
CVE Names:         CVE-2021-29967  

Reference:         ESB-2021.1942
                   ESB-2021.1925

Original Bulletin: 
   http://www.debian.org/lts/security/2021/dla-2673

- --------------------------BEGIN INCLUDED TEXT--------------------

- -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

- - -------------------------------------------------------------------------
Debian LTS Advisory DLA-2673-1                debian-lts@lists.debian.org
https://www.debian.org/lts/security/               Emilio Pozuelo Monfort
June 03, 2021                                 https://wiki.debian.org/LTS
- - -------------------------------------------------------------------------

Package        : firefox-esr
Version        : 78.11.0esr-1~deb9u1
CVE ID         : CVE-2021-29967

Multiple security issues have been found in the Mozilla Firefox
web browser, which could potentially result in the execution
of arbitrary code.

For Debian 9 stretch, this problem has been fixed in version
78.11.0esr-1~deb9u1.

We recommend that you upgrade your firefox-esr packages.

For the detailed security status of firefox-esr please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/firefox-esr

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS
- -----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEEcJymx+vmJZxd92Q+nUbEiOQ2gwIFAmC4ooQACgkQnUbEiOQ2
gwISXQ/8D6iJ+Wr/UYf06QG+zTP9Omg9m/gyHm9M3mq8R73HabXi3QJiEoKVvhIU
DCQCPxUg2yalF3//BWib8ye8RdueZJdYu3DSInQhMheU6VI/jhXTzdHKuT16/NgX
HdWlb4Ph3dJUZMu5vgPVfQNCxNQree362vfqCSp3KXZ7m0YHNgpz+u9UEHgwdkiB
UqNM6tR8qCK62m1LCD1fnpfOqL9NRwJOhNHugnhS7oHacgOBsT4KZ7mYINtHbFJS
/Rv8cBthWq1Hcdg7M0cW1y919zXuzJLr8dczmhmraZvw00hkgVXDBezdbDAMH//d
EVfKKn6p7sN8zLq86QO6acY1DJUMjbJUb1TMd0dqSbwxb/3VMzlJSJuT2hQ/XnTY
GGJ7XcNQRFoL22o7cR/ejwMM/CjJSDXE9QlTGHggBKAGpPrXGfaWsvG6xbXKlAm5
erBegj19FNwOXs0D8SpgMwHc0tkFwe6RoFrr4Zd+8IL8zut0WFoYjwGTzmSVgqAP
bN4HCO4nCXAiHTJ2lSdX/f1mZE0wBGFQLCIUAhci670Gdu4uecG8trj2nyGHXCHe
/XJEVK7+FDdNIq8PaNm4SE7hjcei1RwrcoPTPdW4buOKuRLv2kE7HRUDcYkT0z4k
D72R5XxviDZ/6on+luRk3srYDI+TfD256bDpAUeRyRbsvV9ibJE=
=G9gg
- -----END PGP SIGNATURE-----

- --------------------------END INCLUDED TEXT--------------------

You have received this e-mail bulletin as a result of your organisation's
registration with AusCERT. The mailing list you are subscribed to is
maintained within your organisation, so if you do not wish to continue
receiving these bulletins you should contact your local IT manager. If
you do not know who that is, please send an email to auscert@auscert.org.au
and we will forward your request to the appropriate person.

NOTE: Third Party Rights
This security bulletin is provided as a service to AusCERT's members.  As
AusCERT did not write the document quoted above, AusCERT has had no control
over its content. The decision to follow or act on information or advice
contained in this security bulletin is the responsibility of each user or
organisation, and should be considered in accordance with your organisation's
site policies and procedures. AusCERT takes no responsibility for consequences
which may arise from following or acting on information or advice contained in
this security bulletin.

NOTE: This is only the original release of the security bulletin.  It may
not be updated when updates to the original are made.  If downloading at
a later date, it is recommended that the bulletin is retrieved directly
from the author's website to ensure that the information is still current.

Contact information for the authors of the original document is included
in the Security Bulletin above.  If you have any questions or need further
information, please contact them directly.

Previous advisories and external security bulletins can be retrieved from:

        https://www.auscert.org.au/bulletins/

===========================================================================
Australian Computer Emergency Response Team
The University of Queensland
Brisbane
Qld 4072

Internet Email: auscert@auscert.org.au
Facsimile:      (07) 3365 7031
Telephone:      (07) 3365 4417 (International: +61 7 3365 4417)
                AusCERT personnel answer during Queensland business hours
                which are GMT+10:00 (AEST).
                On call after hours for member emergencies only.
===========================================================================
-----BEGIN PGP SIGNATURE-----
Comment: http://www.auscert.org.au/render.html?it=1967

iQIVAwUBYLmpy+NLKJtyKPYoAQh/FA/+PjCfvSlJgykMh8kSn5+3Mye/l4xep95I
WURVGzahC4rAO7DqUM2k4OS3wtOdhspbMK4DnzjgJyxlvrPdTgHJZmpcBdBchl+9
mAYk6YnnlrMcYO2j9/9l2eCtuRTUdedVeObHJFRTXzrFopq1aSEViTIVsgcEHBjG
2a2hZopbxZjSak8khELxmwbemn96sSfQePZmoP43H1Lun2N5grc/8OpjbaPJ5Jld
Sy1SS29HbQFCnto8Ajzc6X2T8en1LMfsmEQ434tZsfU4KoPPYYSUs7Y3zN0ZT0xc
fPKDk8w8LUbetFGHPcQm3FBmmxy2gN9xG58v9PvpQnA7jkdmQIxj3F8fkPsnFNpr
4/4nUwGQHvRXDNHs/1mTlh3hjodGnMiOU4US+L1L1K/wU6Iw4KVzgzhq6n+HNu9o
t8t8ZW6/SfGMxlaSr1cuml2JKDDFbcKRGZrf/+YGlzwiHEhunvqfOeQha+xklPfS
ERi7SIBqUrKRaPVt/YuK8IPbjYip8FcDr29cxrE0zZySgqx0QpJ9TaIHoGxa8D4l
5s4zprlEqPqLik2KxByuTnUfAtLCkXKjdtORMjlCPlBqsJbpsW3yS4v/Ef288yF5
2bB2dwQUbMKCLkyxBbNSn5zIv+kMc3AgH3lxcWCjHqOal7sDbOGo7QCN0W5fYTSm
Mt/2W+Nmj7w=
=ZLAe
-----END PGP SIGNATURE-----