Debian 10166 Published by

The following updates has been released for Debian GNU/Linux 9:

DSA 4448-1: firefox-esr security update
DSA 4449-1: ffmpeg security update



DSA 4448-1: firefox-esr security update

- -------------------------------------------------------------------------
Debian Security Advisory DSA-4448-1 security@debian.org
https://www.debian.org/security/ Moritz Muehlenhoff
May 22, 2019 https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : firefox-esr
CVE ID : CVE-2018-18511 CVE-2019-5798 CVE-2019-7317 CVE-2019-9797
CVE-2019-9800 CVE-2019-9816 CVE-2019-9817 CVE-2019-9819
CVE-2019-9820 CVE-2019-11691 CVE-2019-11692 CVE-2019-11693
CVE-2019-11698

Multiple security issues have been found in the Mozilla Firefox web
browser, which could potentially result in the execution of arbitrary code.

For the stable distribution (stretch), these problems have been fixed in
version 60.7.0esr-1~deb9u1.

We recommend that you upgrade your firefox-esr packages.

For the detailed security status of firefox-esr please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/firefox-esr

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/



DSA 4449-1: ffmpeg security update

- -------------------------------------------------------------------------
Debian Security Advisory DSA-4449-1 security@debian.org
https://www.debian.org/security/ Moritz Muehlenhoff
May 22, 2019 https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : ffmpeg
CVE ID : CVE-2018-15822 CVE-2018-1999011 CVE-2019-9718
CVE-2019-11338

Several vulnerabilities have been discovered in the FFmpeg multimedia
framework, which could result in denial of service or potentially the
execution of arbitrary code if malformed files/streams are processed.

For the stable distribution (stretch), these problems have been fixed in
version 7:3.2.14-1~deb9u1.

We recommend that you upgrade your ffmpeg packages.

For the detailed security status of ffmpeg please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/ffmpeg

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/