Re: Security advisories sinc 13/0 release

"Bruce Dubbs" ([email protected] via blfs-support Mailing List) <[email protected]> Sat, 25 Apr 2026 12:59:31 -0500
Newsgroups gmane.linux.lfs.beyond.support
Message-ID <[email protected]>
This is a multi-part message in MIME format...

------------=_1777139978-26480-26147
Content-Language: en-US
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit

On 4/25/26 12:50 PM, Charles Meier ([email protected] via blfs-support Mailing 
List) wrote:
> 
> 
> On Thursday, April 16th, 2026 at 3:10 PM, Bruce Dubbs <[email protected]> wrote:
> 
>> In the six weeks since the LFS and BLFS 13.0 releases there have been an
>> inordinately large number of package security releases.
> 
> Having just built all of these on your list, I am not surprised at the quantity given the large number of warnings that went flying by in package after package. Warnings like "Someone is writing 1 or more bytes to a buffer of size 0" or "You declared $X to be const but now you are setting it" should probably be looked at as errors and investigated by the developers rather than simply ignoring them.
> 
> Also, after the /. article on Mozilla's use of Anthropics latest tool, I went and looked to see if there was a new release of Firefox. Sure enough, there is a 140.10.0esr w/ fixes for 10 high rated vulnerabilities.
> 
> https://archive.mozilla.org/pub/firefox/releases/140.10.0esr/source/firefox-140.10.0esr.source.tar.xz

Yes, we know about that update.  Thunderbird too.  We are swamped with updates right 
now and editor availability is limited due to non LFS events.

   -- Bruce


------------=_1777139978-26480-26147
Content-Type: text/plain; charset="UTF-8"
Content-Disposition: inline
Content-Transfer-Encoding: 8bit
MIME-Version: 1.0

-- 
http://lists.linuxfromscratch.org/sympa/info/blfs-support
Unsubscribe: See the above information page

------------=_1777139978-26480-26147--