So I went to update my apps and was greeted with these warnings in FDroid. A quick and basic search online and in various communities yielded no news regarding a major compromise in Fennec and Mull, does anyone know more about this or have you seen any news regarding a vulnerability? Curious if this is a false positive or if there is something going on with firefox forks.

    • youmaynotknow
      link
      fedilink
      113 months ago

      Or you can install directly from Divest via FFupdater, or from their github (I use Obtainium for that).

      • @PunkiBas
        link
        53 months ago

        How do you use obtainium to download from their repo? I’m trying but can’t seem to make it work.

        • @[email protected]
          link
          fedilink
          English
          33 months ago

          When you got add the repo in Obtainium in the overrides section choose Fdroid Third party repo. Then in the app name field type mull

        • youmaynotknow
          link
          fedilink
          2
          edit-2
          3 months ago

          I apologize. I didn’t see that my Obtainium was actually pulling from the fdroid repo. I was able to add it to Obtainium from the Divest repo: https://divestos.org/fdroid/official/us.spotco.fennec_dos_21320020.apk

          But I really doubt that it will trigger updates, since it’s tied to the current version apk.

          I update my browsers and K9 via FFupdater, that’s where my confusion came from. And I thank you for calling me our, I just removed Mull from my Obtainium.

    • TWeaK
      link
      fedilink
      English
      73 months ago

      Ah phew, was wondering why I hadn’t even had the notification.

    • @thebigslime
      link
      13 months ago

      I get an incompatibility error after adding their repo to FDroid.

      • Archy
        link
        83 months ago

        Signatures are different. Uninstall old FDroid version first

  • umami_wasabi
    link
    fedilink
    25
    edit-2
    3 months ago

    It is the recent use after free vuln actively exploited found in FF, which both Fennec and Mull relies as upstream. This compounds on changes made to Android NDK and the source of FF move into the monorepo, making them harder to build. Hence, they’re still vulnerable to the attack.

  • @CrazyLikeGollum
    link
    English
    153 months ago

    Mull at least has been fixed in the divestOS repo. I can’t speak to fennec as I don’t use it.

    The version in the f-droid main repo is behind because of Mozilla changing their repo system thus screwing with the build process and at least for now currently requiring a compiler that doesn’t meet F-Droid’s (IMO slightly ridiculous) standards for allowable software.

  • @[email protected]
    link
    fedilink
    103 months ago

    Mull from divestos repo works fine! Use FFupdater to install it or link the fdroid repo to your fdroid

  • slurp
    link
    fedilink
    103 months ago

    Mull is fine if you use the divestos repo directly, but the f-droid version is behind

      • SomeLemmyUser
        link
        fedilink
        23 months ago

        True, but the config settings should be good Form the get go, that’s the reason the app exitists after all and ublck and noscript are installed fast. But thanks for the tip :)