Re: Firefox and Debian Testing: Getting Security Updates?

From: [KS] (lists04_at_fastmail.fm)
Date: 08/17/05

  • Next message: Maurits van Rees: "Re: Firefox and Debian Testing: Getting Security Updates?"
    Date: Wed, 17 Aug 2005 03:12:29 -0400
    To: debian-users <debian-user@lists.debian.org>
    
    

    a.list.address@gmail.com wrote:
    > I'm a happy user of Testing, but I'm a bit concerned about getting
    > updates to Firefox in a timely manner. The current version in Testing
    > is 1.0.4-2, which has recently-announced vulnerabilities in it. The
    > vulns (I don't like typing that word :) have been fixed in the version
    > in Sarge, 1.0.4-2sarge1. They've been fixed in Unstable as well, in
    > 1.0.6-2.
    >
    > But when will this version come to Testing? A quick look at the
    > changelog for the package shows that 1.0.5-1, which fixes some
    > security issues, was uploaded to Unstable on July 16th with an urgency
    > level of high, but four days later 1.0.6-1 was uploaded with an
    > urgency of low. Ten days later, on July 30th, 1.0.6-2 was uploaded
    > with an urgency of medium. But here it is over two weeks later, and
    > Testing is still stuck on 1.0.4-2.
    >
    > I looked in the bug tracker, but I couldn't find any good bug to
    > prevent these newer versions from moving to Testing.
    >
    > Now, I'm far from an expert, and I'm still fairly new to Debian (less
    > than a year), but it seems like something needs to change. I don't
    > want to run Unstable on my computer, but I don't want to be stuck with
    > vulnerable browsers either.
    >
    > I could upgrade Firefox to the version that's in unstable, but there
    > are two problems:
    >
    > 1) This is a poor long-term solution, having to manually upgrade
    > packages and their dependencies to fix security problems;
    >
    > 2) I can't even do that in this case, because Firefox 1.0.6-2 depends
    > on libxinerama1, which depends on libc6 >=2.3.5, but Testing is still
    > on libc6 2.3.2.
    >
    > This is simply a mess. Actually, now that I think about it, I suppose
    > the reason 1.0.6-2 hasn't moved into Testing is because of the
    > dependency problem of libxinerama1 and libc6. But who knows when the
    > new version of libc6 will get into Testing? It may be a very long
    > time. In the meantime, are we Testing users supposed to keep using a
    > vulnerable version of Firefox?
    >
    > I know Testing is not supported for security updates, but for
    > high-profile packages like Firefox with high-profile vulns, don't we
    > need a solution for this problem? And upgrading to Unstable is not a
    > solution; there's a reason I and others use Testing instead of
    > Unstable.
    >

    Although I'm don't have much advice for you on this topic, but I
    recommend you to go over to the debian-security mailing list and read
    the thread http://lists.debian.org/debian-security/2005/07/msg00315.html
    about mozilla-* security support state of affairs.

    A very long thread on a valid topic and pretty informative.

    /KS

    -- 
    To UNSUBSCRIBE, email to debian-user-REQUEST@lists.debian.org 
    with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org
    

  • Next message: Maurits van Rees: "Re: Firefox and Debian Testing: Getting Security Updates?"

    Relevant Pages

    • Re: kde 3.x to 3.3
      ... >> In general if you want newer versions of products (other than security ... you will need to upgrade to a newer version of SuSE or install ... where even security fixes need to be tested ... >> no revenue, no SuSE, no YOU updates... ...
      (alt.os.linux.suse)
    • FC3 Yum & Firefox
      ... According to Firefox, I'm running ver 1.0.2. ... If I try yum upgrade firefox, it says there are no updates. ...
      (Fedora)
    • Re: Mozilla Firefox
      ... Firefox has an automatic update built in. ... Automatic updates may cover Firefox but what about any plugins the user ... >> FWIW Since XP SP1 IE uses Sun Java. ... computer security. ...
      (microsoft.public.windows.inetexplorer.ie6.browser)
    • Re: Firefox and Debian Testing: Getting Security Updates?
      ... > updates to Firefox in a timely manner. ... > security issues, was uploaded to Unstable on July 16th with an urgency ... > I could upgrade Firefox to the version that's in unstable, ...
      (Debian-User)
    • Re: Security Updates -- Are they necessary in Linux for user?
      ... Not all of those 213 updates are necessarilly for security flaws. ... Some may be for bugs that cause programs to behave incorrectly or crash, and a few may install upgraded versions of programs with new features. ... For instance, if you are browsing the internet with an old version of Firefox with a security flaw, it may be possible for a malicious website to run code that would allow someone to take control of your system ...
      (Fedora)