Package firefox-esr: Information

  • Default inline alert: Version in the repository: 140.6.0-alt1

Source package: firefox-esr
Version: 128.8.1-alt1
Latest version according to Repology
Build time:  Mar 30, 2025, 01:15 PM in the task #379697
Category: Networking/WWW
Report package bug
License: MPL-2.0
Summary: The Mozilla Firefox project is a redesign of Mozilla's browser
Description: 
Mozilla Firefox is an open-source web browser, designed
for standards compliance, performance and portability.

List of RPM packages built from this SRPM:
firefox-esr (x86_64, i586, aarch64)
firefox-esr-config-privacy (x86_64, i586, aarch64)
firefox-esr-debuginfo (x86_64, i586, aarch64)

Maintainer: Pavel Vasenkov



    1. /dev/shm
    2. python3(hamcrest)
    3. libwireless-devel
    4. /proc
    5. lld17.0-devel
    6. llvm17.0-devel
    7. mozilla-common-devel
    8. nasm
    9. node
    10. python3(pip)
    11. alternatives
    12. python3(setuptools)
    13. rpm-build-firefox
    14. python3(sqlite3)
    15. libnss-devel-static
    16. rpm-macros-alternatives
    17. browser-plugins-npapi-devel
    18. cbindgen
    19. chrpath
    20. clang17.0
    21. clang17.0-devel
    22. python3-base
    23. libshell
    24. libstdc++-devel
    25. pkgconfig(alsa)
    26. pkgconfig(aom)
    27. pkgconfig(bzip2)
    28. pkgconfig(cairo)
    29. pkgconfig(dav1d)
    30. pkgconfig(dbus-1)
    31. pkgconfig(dbus-glib-1)
    32. pkgconfig(dri)
    33. pkgconfig(fontconfig)
    34. pkgconfig(freetype2)
    35. pkgconfig(gio-2.0)
    36. pkgconfig(graphite2)
    37. pkgconfig(gtk+-3.0)
    38. pkgconfig(harfbuzz)
    39. pkgconfig(hunspell)
    40. pkgconfig(icu-i18n)
    41. pkgconfig(libcurl)
    42. pkgconfig(libdrm)
    43. pkgconfig(libevent)
    44. pkgconfig(libffi)
    45. pkgconfig(libjpeg)
    46. pkgconfig(libnotify)
    47. pkgconfig(libproxy-1.0)
    48. pkgconfig(libpulse)
    49. rust >= 1.65.0
    50. pkgconfig(libstartup-notification-1.0)
    51. rust-cargo >= 1.65.0
    52. pkgconfig(nspr) >= 4.35
    53. pkgconfig(nss) >= 3.98
    54. pkgconfig(opus)
    55. pkgconfig(pixman-1)
    56. pkgconfig(vpx)
    57. pkgconfig(x11)
    58. pkgconfig(xcomposite)
    59. pkgconfig(xcursor)
    60. pkgconfig(xdamage)
    61. pkgconfig(xext)
    62. pkgconfig(xft)
    63. pkgconfig(xi)
    64. pkgconfig(xkbcommon)
    65. pkgconfig(xrandr)
    66. pkgconfig(xscrnsaver)
    67. pkgconfig(xt)
    68. pkgconfig(xtst)
    69. pkgconfig(zlib)
    70. unzip
    71. xorg-cf-files
    72. yasm
    73. zip
    74. gst-plugins1.0-devel
    75. gstreamer1.0-devel
    76. python3(click)
    77. glibc-kernheaders-generic
    78. python3(curses)

Last changed


March 29, 2025 Pavel Vasenkov 128.8.1-alt1
- New ESR version.
- Security fixes:
  + CVE-2025-2857 Incorrect handle could lead to sandbox escapes
March 4, 2025 Pavel Vasenkov 128.8.0-alt1
- New ESR version.
- Security fixes:
  + CVE-2024-43097 Overflow when growing an SkRegion's RunArray
  + CVE-2025-1930 AudioIPC StreamData could trigger a use-after-free in the Browser process
  + CVE-2025-1931 Use-after-free in WebTransportChild
  + CVE-2025-1932 Inconsistent comparator in XSLT sorting led to out-of-bounds access
  + CVE-2025-1933 JIT corruption of WASM i32 return values on 64-bit CPUs
  + CVE-2025-1934 Unexpected GC during RegExp bailout processing
  + CVE-2025-1935 Clickjacking the registerProtocolHandler info-bar
  + CVE-2025-1936 Adding %00 and a fake extension to a jar: URL changed the interpretation of the contents
  + CVE-2025-1937 Memory safety bugs fixed in Firefox 136, Thunderbird 136, Firefox ESR 115.21, Firefox ESR 128.8, and Thunderbird 128.8
  + CVE-2025-1938 Memory safety bugs fixed in Firefox 136, Thunderbird 136, Firefox ESR 128.8, and Thunderbird 128.8
Feb. 13, 2025 Pavel Vasenkov 128.7.0-alt1
- New ESR version.
- Security fixes:
  + CVE-2025-1009 Use-after-free in XSLT
  + CVE-2025-1010 Use-after-free in Custom Highlight
  + CVE-2025-1011 A bug in WebAssembly code generation could result in a crash
  + CVE-2025-1012 Use-after-free during concurrent delazification
  + CVE-2024-11704 Potential double-free vulnerability in PKCS#7 decryption handling
  + CVE-2025-1013 Potential opening of private browsing tabs in normal browsing windows
  + CVE-2025-1014 Certificate length was not properly checked
  + CVE-2025-1016 Memory safety bugs fixed in Firefox 135, Thunderbird 135, Firefox ESR 115.20, Firefox ESR 128.7, Thunderbird 115.20, and
  + CVE-2025-1017 Memory safety bugs fixed in Firefox 135, Thunderbird 135, Firefox ESR 128.7, and Thunderbird 128.7