| Errata ID | 270 |
|---|---|
| Date | 2018-10-10 |
| Source package | firefox-esr |
| Fixed in version | 60.2.2esr-1~deb9u1 |
| Description | This update addresses the following issues: * Type confusion in JavaScript (CVE-2018-12386) * stack out-of-bounds read in Array.prototype.push (CVE-2018-12387) |
| Additional notes | |
| CVE ID | CVE-2018-12386 CVE-2018-12387 |
| UCS Bug number | #47904 |
