• kbal
    link
    fedilink
    1927 days ago

    It’s probably related to this: https://gitlab.com/relan/fennecbuild/-/merge_requests/63

    F-droid Fennec had build problems lately due to google removing big dependencies from its android package repo or whatever, so it’s well out of date for now. The latest version there has at least that one well-known security problem that was in the news a few weeks ago. I don’t know why you’re getting notified about it now, I have it installed and didn’t see that. But if you’re risk-averse then you probably shouldn’t currently be using it to visit websites that might be malicious.

    Recent comments over there suggest that progress is being made at last.

    • @[email protected]
      link
      fedilink
      327 days ago

      I use mull from f-droid, and f-droid started showing that when upgrading Today to version 1.21.1. No idea why until this f-droid app upgrade.

      I guess the mull issue is the same. Both fennec and mull are at the same version on f-droid, 129.0.2, and both show in their anti-features that the app contains a known security vulnerability, indicating firefox has fixed several security vulnerabilities since 130.

      Is it right to hope that once fennec can get distributed on f-droid, then mull will follow? I’m not planning to move away from mull.

      Thanks !

      • merde alors
        link
        fedilink
        3
        edit-2
        26 days ago

        I use mull from f-droid, and f-droid started showing that when upgrading Today to version 1.21.1. No idea why until this f-droid app upgrade.

        I guess the mull issue is the same. Both fennec and mull are at the same version on f-droid, 129.0.2, and both show in their anti-features that the app contains a known security vulnerability, indicating firefox has fixed several security vulnerabilities since 130.

        divestOS repo is on 131.0.3 for mull

  • @[email protected]
    link
    fedilink
    English
    527 days ago

    Wasn’t Fennec a couple of major revisions behind due to build issues, and one of said major revisions was a zero-day fix, so yeah, Fennec would be vulnerable.

    (I dumped it about two weeks ago once I noticed that it was behind the security patch curve.)

    • Possibly linux
      link
      fedilink
      English
      526 days ago

      Next time make a post 2 weeks ago. Best to voice concern over things you notice. The person who discovered the XZ backdoor did that and it caught a disaster.

      • @[email protected]
        link
        fedilink
        English
        126 days ago

        Fennec being a delayed build has been a thing for years at this point: it’s a pain in the ass to get built and in f-droid. I mean, just google ‘fennec f-droid out of date’ and you’ll see people talking about this going back to 2020.

        I didn’t exactly find a stunning shocking unknown thing: Fennec is slow on builds, it got outdated, there was a zero-day in older Firefox versions, and so bam: there’s a security issue in Fennec.

        Might be worth adding the Firefox security RSS feed for anyone using Firefox or a derivative browser so that you’ve got the best information about issues like this.

    • @ImhotepOP
      link
      127 days ago

      So what do you use instead?

        • @ImhotepOP
          link
          227 days ago

          From the Play store/Aurora, or is there another way? I remember an app on fdroid that would install different mozilla browsers but I can’t find it

  • Possibly linux
    link
    fedilink
    English
    2
    edit-2
    26 days ago

    Don’t use the unpatched version. I’d uninstall it personally. I fixed mine (Mull) by switching to the Divest repo.