DSA-3477-1 iceweasel -- security update

Related Vulnerabilities: CVE-2016-1523   CVE-2016-1526  

Holger Fuhrmannek discovered that missing input sanitising in the Graphite font rendering engine could result in the execution of arbitrary code. For the oldstable distribution (wheezy), this problem has been fixed in version 38.6.1esr-1~deb7u1. For the stable distribution (jessie), this problem has been fixed in version 38.6.1esr-1~deb8u1. For the unstable distribution (sid), this problem has been fixed in version 44.0-1. We recommend that you upgrade your iceweasel packages.

Debian Security Advisory

DSA-3477-1 iceweasel -- security update

Date Reported:
14 Feb 2016
Affected Packages:
iceweasel
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2016-1523, CVE-2016-1526.
More information:

Holger Fuhrmannek discovered that missing input sanitising in the Graphite font rendering engine could result in the execution of arbitrary code.

For the oldstable distribution (wheezy), this problem has been fixed in version 38.6.1esr-1~deb7u1.

For the stable distribution (jessie), this problem has been fixed in version 38.6.1esr-1~deb8u1.

For the unstable distribution (sid), this problem has been fixed in version 44.0-1.

We recommend that you upgrade your iceweasel packages.