Debian 10225 Published by

The following updates has been released for Debian 7 LTS:

[DLA 906-1] firefox-esr security update
[DLA 907-1] xen security update



[DLA 906-1] firefox-esr security update

Package : firefox-esr
Version : 45.9.0esr-1~deb7u1
CVE ID : CVE-2017-5429 CVE-2017-5432 CVE-2017-5433 CVE-2017-5434
CVE-2017-5435 CVE-2017-5436 CVE-2017-5438 CVE-2017-5439
CVE-2017-5440 CVE-2017-5441 CVE-2017-5442 CVE-2017-5443
CVE-2017-5444 CVE-2017-5445 CVE-2017-5446 CVE-2017-5447
CVE-2017-5448 CVE-2017-5459 CVE-2017-5460 CVE-2017-5461
CVE-2017-5462 CVE-2017-5464 CVE-2017-5465 CVE-2017-5469

Multiple security issues have been found in the Mozilla Firefox web
browser: Multiple memory safety errors, use-after-frees, buffer
overflows and other implementation errors may lead to the execution of
arbitrary code, information disclosure or denial of service.

For Debian 7 "Wheezy", these problems have been fixed in version
45.9.0esr-1~deb7u1.

We recommend that you upgrade your firefox-esr packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS

[DLA 907-1] xen security update

Package : xen
Version : 4.1.6.lts1-6
CVE ID : CVE-2017-7228
Debian Bug : #859560

CVE-2017-7228 (XSA-212)

An insufficient check on XENMEM_exchange may allow PV guests to access
all of system memory.

For Debian 7 "Wheezy", these problems have been fixed in version
4.1.6.lts1-6.

We recommend that you upgrade your xen packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS