From mboxrd@z Thu Jan 1 00:00:00 1970 From: Ricardo Wurmus Subject: Re: Unpatched security flaws in GNU IceCat 38 Date: Thu, 4 Aug 2016 11:18:20 +0200 Message-ID: References: <87lh0dz106.fsf@netris.org> Mime-Version: 1.0 Content-Type: text/plain Return-path: Received: from eggs.gnu.org ([2001:4830:134:3::10]:35439) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1bVEnT-0004kT-6f for guix-devel@gnu.org; Thu, 04 Aug 2016 05:18:36 -0400 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1bVEnP-0007xZ-07 for guix-devel@gnu.org; Thu, 04 Aug 2016 05:18:34 -0400 Received: from sinope02.bbbm.mdc-berlin.de ([141.80.25.24]:56277) by eggs.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1bVEnO-0007vz-MG for guix-devel@gnu.org; Thu, 04 Aug 2016 05:18:30 -0400 In-Reply-To: <87lh0dz106.fsf@netris.org> List-Id: "Development of GNU Guix and the GNU System distribution." List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: guix-devel-bounces+gcggd-guix-devel=m.gmane.org@gnu.org Sender: "Guix-devel" To: Mark H Weaver Cc: guix-devel@gnu.org Mark H Weaver writes: > I'm sorry to report that GNU IceCat 38 can no longer be safely used, due > to critical security flaws that are believed to allow remote code > execution. I was unable to backport upstream fixes from 45.3 to 38. > > Until IceCat 45.3 is available, I recommend that you use Epiphany. Thanks, Mark, for the heads-up. Since our package for Conkeror also uses IceCat under the hood I suppose our version of Conkeror also cannot be safely used at this point. ~~ Ricardo