Re: Debian testing/unstable users: beware of Firefox critical CVEs

2024-03-26 Thread Andreas Metzler
On 2024-03-24 Samuel Henrique wrote: > Hello everyone, > Given our current time_t transition happening, which means packages > are blocked from migrating to testing for weeks, and that unstable > updates have become harder to apply, two critical CVE fixes for > Firefox became impossible to get

Re: Debian testing/unstable users: beware of Firefox critical CVEs

2024-03-25 Thread Samuel Henrique
> On 24-03-2024 11:45 p.m., Samuel Henrique wrote: > > In a recent case, the issue was addressed by performing a > > testing-proposed-update of the package. This would allow firefox-esr to be > > fixed on testing before the transition is over, but it would not work for > > those > > installing

Re: Debian testing/unstable users: beware of Firefox critical CVEs

2024-03-25 Thread Paul Gevers
Hi Samuel, On 24-03-2024 11:45 p.m., Samuel Henrique wrote: In a recent case, the issue was addressed by performing a testing-proposed-update of the package. This would allow firefox-esr to be fixed on testing before the transition is over, but it would not work for those installing the firefox

Re: Debian testing/unstable users: beware of Firefox critical CVEs

2024-03-25 Thread Hakan Bayındır
I moved to Mozilla's official packages for the time being since I didn't want to downgrade to ESR for now. Will resume with Debian's packages when the dust settles down. On 25.03.2024 ÖÖ 8:26, Leandro Cunha wrote: Hi, On Mon, Mar 25, 2024 at 2:18 AM Paul Wise wrote: On Sun, 2024-03-24 at

Re: Debian testing/unstable users: beware of Firefox critical CVEs

2024-03-24 Thread Leandro Cunha
Hi, On Mon, Mar 25, 2024 at 2:18 AM Paul Wise wrote: > > On Sun, 2024-03-24 at 22:45 +, Samuel Henrique wrote: > > > I'm sending this to d-devel because there should be a lot of testing and > > unstable users on this list. If you're not running firefox 124.0.1 or > > firefox-esr

Re: Debian testing/unstable users: beware of Firefox critical CVEs

2024-03-24 Thread Paul Wise
On Sun, 2024-03-24 at 22:45 +, Samuel Henrique wrote: > I'm sending this to d-devel because there should be a lot of testing and > unstable users on this list. If you're not running firefox 124.0.1 or > firefox-esr 115.9.1esr-1, you should find a way of upgrading to those > versions.

Debian testing/unstable users: beware of Firefox critical CVEs

2024-03-24 Thread Samuel Henrique
Hello everyone, Given our current time_t transition happening, which means packages are blocked from migrating to testing for weeks, and that unstable updates have become harder to apply, two critical CVE fixes for Firefox became impossible to get it through the official repositories: