GNU bug report logs - #73669
Firefox ESR 115 branch is now deprecated for GNU/Linux and needs to move on to the 128 branch

Previous Next

Package: gnuzilla;

Reported by: Nin Gen <0xningen <at> gmail.com>

Date: Mon, 7 Oct 2024 00:10:02 UTC

Severity: normal

To reply to this bug, email your comments to 73669 AT debbugs.gnu.org.

Toggle the display of automated, internal messages from the tracker.

View this report as an mbox folder, status mbox, maintainer mbox


Report forwarded to bug-gnuzilla <at> gnu.org:
bug#73669; Package gnuzilla. (Mon, 07 Oct 2024 00:10:02 GMT) Full text and rfc822 format available.

Acknowledgement sent to Nin Gen <0xningen <at> gmail.com>:
New bug report received and forwarded. Copy sent to bug-gnuzilla <at> gnu.org. (Mon, 07 Oct 2024 00:10:02 GMT) Full text and rfc822 format available.

Message #5 received at submit <at> debbugs.gnu.org (full text, mbox):

From: Nin Gen <0xningen <at> gmail.com>
To: bug-gnuzilla <at> gnu.org
Subject: Firefox ESR 115 branch is now deprecated for GNU/Linux and needs to
 move on to the 128 branch
Date: Mon, 7 Oct 2024 00:09:28 +0000
[Message part 1 (text/plain, inline)]
Version 115.16.0, first offered to ESR channel users on October 1, 2024

Firefox ESR 115 is now supported only on Windows 7-8.1 and macOS
10.12-10.14. Users on other operating systems should use Firefox ESR 128
instead.
source: https://www.mozilla.org/en-US/firefox/115.16.0/releasenotes/
[Message part 2 (text/html, inline)]

Information forwarded to bug-gnuzilla <at> gnu.org:
bug#73669; Package gnuzilla. (Wed, 27 Nov 2024 00:18:01 GMT) Full text and rfc822 format available.

Message #8 received at 73669 <at> debbugs.gnu.org (full text, mbox):

From: Mark H Weaver <mhw <at> netris.org>
To: Nin Gen <0xningen <at> gmail.com>, 73669 <at> debbugs.gnu.org
Subject: Re: bug#73669: Firefox ESR 115 branch is now deprecated for
 GNU/Linux and needs to move on to the 128 branch
Date: Tue, 26 Nov 2024 19:17:41 -0500
Hi,

Nin Gen <0xningen <at> gmail.com> writes:

> Version 115.16.0, first offered to ESR channel users on October 1, 2024
>
> Firefox ESR 115 is now supported only on Windows 7-8.1 and macOS
> 10.12-10.14. Users on other operating systems should use Firefox ESR 128
> instead.
> source: https://www.mozilla.org/en-US/firefox/115.16.0/releasenotes/

Thanks for this report.

I've not been overly concerned about this, because during my 10 years of
maintaining the IceCat package in GNU Guix, I've noticed that it is rare
for Firefox ESR security updates to affect only GNU/Linux systems.
Moreover, I expect that security flaws in the GNU/Linux-specific code of
ESR 115 most likely also exist in ESR 128, and if such a flaw were
discovered, it would be publicized by Mozilla in connection with ESR
128.  As of now, that has not happened.

I've been more concerned about the possibility of malicious
functionality that might have been added in the upstream ESR 128 branch
relative to ESR 115.

That said, I acknowledge that this is not a satisfactory situation,
especially given that the published list of bug fixes in 115.18.0esr
(mfsa2024-65) is unexpectedly short compared to the fixes in 128.5.0esr
(mfsa2024-64).

I will start working on the IceCat 128 branch in the next few days.

    Best regards,
        Mark




This bug report was last modified 205 days ago.

Previous Next


GNU bug tracking system
Copyright (C) 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson.