Errata overview
Errata ID 270
Date 2018-10-10
Source package firefox-esr
Fixed in version 60.2.2esr-1~deb9u1
Description
This update addresses the following issues:
* Type confusion in JavaScript (CVE-2018-12386)
* stack out-of-bounds read in Array.prototype.push (CVE-2018-12387)
Additional notes
CVE ID CVE-2018-12386
CVE-2018-12387
UCS Bug number #47904