Package firefox-esr: Information
Default inline alert: Version in the repository: 140.6.0-alt1
Source package: firefox-esr
Version: 128.8.1-alt1
Build time: Mar 30, 2025, 01:15 PM in the task #379697
Category: Networking/WWW
Report package bugHome page: https://www.mozilla.org/firefox/
License: MPL-2.0
Summary: The Mozilla Firefox project is a redesign of Mozilla's browser
Description:
Mozilla Firefox is an open-source web browser, designed for standards compliance, performance and portability.
List of RPM packages built from this SRPM:
firefox-esr (x86_64, i586, aarch64)
firefox-esr-config-privacy (x86_64, i586, aarch64)
firefox-esr-debuginfo (x86_64, i586, aarch64)
firefox-esr (x86_64, i586, aarch64)
firefox-esr-config-privacy (x86_64, i586, aarch64)
firefox-esr-debuginfo (x86_64, i586, aarch64)
Maintainer: Pavel Vasenkov
List of contributors:
Pavel Vasenkov
Ajrat Makhmutov
Andrey Cherepanov
Alexey Sheplyakov
Grigory Ustinov
Alexey Gladkov
Gleb Fotengauer-Malinovskiy
Ivan Zakharyaschev
Pavel Vasenkov
Ajrat Makhmutov
Andrey Cherepanov
Alexey Sheplyakov
Grigory Ustinov
Alexey Gladkov
Gleb Fotengauer-Malinovskiy
Ivan Zakharyaschev
Last changed
March 29, 2025 Pavel Vasenkov 128.8.1-alt1
- New ESR version. - Security fixes: + CVE-2025-2857 Incorrect handle could lead to sandbox escapes
March 4, 2025 Pavel Vasenkov 128.8.0-alt1
- New ESR version. - Security fixes: + CVE-2024-43097 Overflow when growing an SkRegion's RunArray + CVE-2025-1930 AudioIPC StreamData could trigger a use-after-free in the Browser process + CVE-2025-1931 Use-after-free in WebTransportChild + CVE-2025-1932 Inconsistent comparator in XSLT sorting led to out-of-bounds access + CVE-2025-1933 JIT corruption of WASM i32 return values on 64-bit CPUs + CVE-2025-1934 Unexpected GC during RegExp bailout processing + CVE-2025-1935 Clickjacking the registerProtocolHandler info-bar + CVE-2025-1936 Adding %00 and a fake extension to a jar: URL changed the interpretation of the contents + CVE-2025-1937 Memory safety bugs fixed in Firefox 136, Thunderbird 136, Firefox ESR 115.21, Firefox ESR 128.8, and Thunderbird 128.8 + CVE-2025-1938 Memory safety bugs fixed in Firefox 136, Thunderbird 136, Firefox ESR 128.8, and Thunderbird 128.8
Feb. 13, 2025 Pavel Vasenkov 128.7.0-alt1
- New ESR version. - Security fixes: + CVE-2025-1009 Use-after-free in XSLT + CVE-2025-1010 Use-after-free in Custom Highlight + CVE-2025-1011 A bug in WebAssembly code generation could result in a crash + CVE-2025-1012 Use-after-free during concurrent delazification + CVE-2024-11704 Potential double-free vulnerability in PKCS#7 decryption handling + CVE-2025-1013 Potential opening of private browsing tabs in normal browsing windows + CVE-2025-1014 Certificate length was not properly checked + CVE-2025-1016 Memory safety bugs fixed in Firefox 135, Thunderbird 135, Firefox ESR 115.20, Firefox ESR 128.7, Thunderbird 115.20, and + CVE-2025-1017 Memory safety bugs fixed in Firefox 135, Thunderbird 135, Firefox ESR 128.7, and Thunderbird 128.7