Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.704220
Category:Debian Local Security Checks
Title:Debian: Security Advisory (DSA-4220-1)
Summary:The remote host is missing an update for the Debian 'firefox-esr' package(s) announced via the DSA-4220-1 advisory.
Description:Summary:
The remote host is missing an update for the Debian 'firefox-esr' package(s) announced via the DSA-4220-1 advisory.

Vulnerability Insight:
Ivan Fratric discovered a buffer overflow in the Skia graphics library used by Firefox, which could result in the execution of arbitrary code.

For the oldstable distribution (jessie), this problem has been fixed in version 52.8.1esr-1~
deb8u1.

For the stable distribution (stretch), this problem has been fixed in version 52.8.1esr-1~
deb9u1.

We recommend that you upgrade your firefox-esr packages.

For the detailed security status of firefox-esr please refer to its security tracker page at: [link moved to references]

Affected Software/OS:
'firefox-esr' package(s) on Debian 8, Debian 9.

Solution:
Please install the updated package(s).

CVSS Score:
6.8

CVSS Vector:
AV:N/AC:M/Au:N/C:P/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2018-6126
BugTraq ID: 104309
http://www.securityfocus.com/bid/104309
BugTraq ID: 104411
http://www.securityfocus.com/bid/104411
Debian Security Information: DSA-4220 (Google Search)
https://www.debian.org/security/2018/dsa-4220
Debian Security Information: DSA-4237 (Google Search)
https://www.debian.org/security/2018/dsa-4237
https://www.exploit-db.com/exploits/45098/
https://security.gentoo.org/glsa/201810-01
https://crbug.com/844457
RedHat Security Advisories: RHSA-2018:1815
https://access.redhat.com/errata/RHSA-2018:1815
RedHat Security Advisories: RHSA-2018:2112
https://access.redhat.com/errata/RHSA-2018:2112
RedHat Security Advisories: RHSA-2018:2113
https://access.redhat.com/errata/RHSA-2018:2113
http://www.securitytracker.com/id/1041014
http://www.securitytracker.com/id/1041046
CopyrightCopyright (C) 2018 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.