Errata overview
Errata ID 416
Date 2020-01-15
Source package firefox-esr
Fixed in version 68.4.1esr-1~deb9u1
Description
This update addresses the following issues:
* Bypass of @namespace CSS sanitization during pasting (CVE-2019-17016)
* Type Confusion in XPCVariant.cpp (CVE-2019-17017)
* CSS sanitization does not escape HTML tags (CVE-2019-17022)
* Memory safety bugs fixed in Firefox 72 and Firefox ESR 68.4
  (CVE-2019-17024)
* IonMonkey type confusion with StoreElementHole and FallibleStoreElement
  (CVE-2019-17026)
Additional notes
CVE ID CVE-2019-17016
CVE-2019-17017
CVE-2019-17022
CVE-2019-17024
CVE-2019-17026
UCS Bug number #50702