Re: Security advisories sinc 13/0 release

"Charles Meier" ([email protected] via blfs-support Mailing List) <[email protected]> Sat, 25 Apr 2026 17:50:27 +0000
Newsgroups gmane.linux.lfs.beyond.support
Message-ID <_cCTjvH9gZLe3mrEa8k19eagc_hpS7VLridPX--j4RnxTxzkTvOzKabwnjFxtS7vH_05-vIbZbELb3_kHFUtbRzNyprkDYOlfc-vzvm5NmI=@protonmail.com>
This is a multi-part message in MIME format...

------------=_1777139438-26502-26132
Content-Type: text/plain; charset=utf-8
Content-Transfer-Encoding: quoted-printable



On Thursday, April 16th, 2026 at 3:10 PM, Bruce Dubbs <[email protected]=
inuxfromscratch.org> wrote:

> In the six weeks since the LFS and BLFS 13.0 releases there have been an
> inordinately large number of package security releases.

Having just built all of these on your list, I am not surprised at the quan=
tity given the large number of warnings that went flying by in package afte=
r package. Warnings like "Someone is writing 1 or more bytes to a buffer of=
 size 0" or "You declared $X to be const but now you are setting it" should=
 probably be looked at as errors and investigated by the developers rather =
than simply ignoring them.

Also, after the /. article on Mozilla's use of Anthropics latest tool, I we=
nt and looked to see if there was a new release of Firefox. Sure enough, th=
ere is a 140.10.0esr w/ fixes for 10 high rated vulnerabilities.

https://archive.mozilla.org/pub/firefox/releases/140.10.0esr/source/firefox=
-140.10.0esr.source.tar.xz

Charles (Chuck) Meier
[email protected]


------------=_1777139438-26502-26132
Content-Type: text/plain; charset="UTF-8"
Content-Disposition: inline
Content-Transfer-Encoding: 8bit
MIME-Version: 1.0

-- 
http://lists.linuxfromscratch.org/sympa/info/blfs-support
Unsubscribe: See the above information page

------------=_1777139438-26502-26132--