| Errata ID | 416 |
|---|---|
| Date | 2020-01-15 |
| Source package | firefox-esr |
| Fixed in version | 68.4.1esr-1~deb9u1 |
| Description | This update addresses the following issues: * Bypass of @namespace CSS sanitization during pasting (CVE-2019-17016) * Type Confusion in XPCVariant.cpp (CVE-2019-17017) * CSS sanitization does not escape HTML tags (CVE-2019-17022) * Memory safety bugs fixed in Firefox 72 and Firefox ESR 68.4 (CVE-2019-17024) * IonMonkey type confusion with StoreElementHole and FallibleStoreElement (CVE-2019-17026) |
| Additional notes | |
| CVE ID | CVE-2019-17016 CVE-2019-17017 CVE-2019-17022 CVE-2019-17024 CVE-2019-17026 |
| UCS Bug number | #50702 |
