[Gnome22-user] Mozilla and Galeon Security

James Strandboge jamie at tpptraining.com
Mon Aug 22 12:31:32 UTC 2005


Mozilla 1.4 and Galeon Security Status
--------------------------------------

The gnome2.2 backport of mozilla is a 1.4 series version that is no
longer maintained by mozilla developers.  A few developers from Sun and
RedHat have chosen to maintain the mozilla-1.4 branch for some time, but
CVS activity in this branch is currently very low.  Backporting patches
from other series is complicated, because the codebases for various
versions of mozilla are very different.  There are known security
vulnerabilites with the version of mozilla that is in the backport.
Galeon, which is based on this version of mozilla, is also affected. 


Resolution
----------

Security patches will not be provided for mozilla and galeon as
contained in the gnome2.2 backport.  Mozilla and galeon will still be
provided for compatibility reasons, but a security warning advising
users of the problem will be shown when installing galeon and
mozilla-browser.

At this time, it is recommended that you install and use mozilla-firefox
from the gnome2.2 backport instead, as it will receive regular security
updates.  


Jamie Strandboge




More information about the Gnome22-user mailing list