Package firefox-esr: Information
Source package: firefox-esr
Version: 140.7.0-alt3
Build time: Jan 24, 2026, 03:45 PM in the task #405832
Category: Networking/WWW
Report package bugHome page: https://www.mozilla.org/firefox/
License: MPL-2.0
Summary: The Mozilla Firefox project is a redesign of Mozilla's browser
Description:
Mozilla Firefox is an open-source web browser, designed for standards compliance, performance and portability.
List of RPM packages built from this SRPM:
firefox-esr (x86_64, i586, aarch64)
firefox-esr-config-privacy (x86_64, i586, aarch64)
firefox-esr-debuginfo (x86_64, i586, aarch64)
firefox-esr (x86_64, i586, aarch64)
firefox-esr-config-privacy (x86_64, i586, aarch64)
firefox-esr-debuginfo (x86_64, i586, aarch64)
Maintainer: Michael Shigorin
List of contributors:
Michael Shigorin
Pavel Vasenkov
Andrey Cherepanov
Ajrat Makhmutov
Alexey Sheplyakov
Grigory Ustinov
Alexey Gladkov
Gleb Fotengauer-Malinovskiy
Ivan Zakharyaschev
Michael Shigorin
Pavel Vasenkov
Andrey Cherepanov
Ajrat Makhmutov
Alexey Sheplyakov
Grigory Ustinov
Alexey Gladkov
Gleb Fotengauer-Malinovskiy
Ivan Zakharyaschev
Last changed
Jan. 22, 2026 Michael Shigorin 140.7.0-alt3
- Fix "new version means new blank profile" (Closes: #57602) + thanks NixOS guys, see http://github.com/NixOS/nixpkgs/pull/119849
Jan. 22, 2026 Michael Shigorin 140.7.0-alt2
- Get yandex search back through default policy (Closes: #45190; see also: #43516; thanks Ruslan Gilfanov).
Jan. 14, 2026 Pavel Vasenkov 140.7.0-alt1
- New ESR version. - Security fixes: + CVE-2026-0877 Mitigation bypass in the DOM: Security component + CVE-2026-0878 Sandbox escape due to incorrect boundary conditions in the Graphics: CanvasWebGL component + CVE-2026-0879 Sandbox escape due to incorrect boundary conditions in the Graphics component + CVE-2026-0880 Sandbox escape due to integer overflow in the Graphics component + CVE-2026-0882 Use-after-free in the IPC component + CVE-2025-14327 Spoofing issue in the Downloads Panel component + CVE-2026-0883 Information disclosure in the Networking component + CVE-2026-0884 Use-after-free in the JavaScript Engine component + CVE-2026-0885 Use-after-free in the JavaScript: GC component + CVE-2026-0886 Incorrect boundary conditions in the Graphics component + CVE-2026-0887 Clickjacking issue, information disclosure in the PDF Viewer component + CVE-2026-0890 Spoofing issue in the DOM: Copy & Paste and Drag & Drop component + CVE-2026-0891 Memory safety bugs fixed in Firefox ESR 140.7, Thunderbird ESR 140.7, Firefox 147 and Thunderbird 147