我们从2011年坚守至今,只想做存粹的技术论坛。  由于网站在外面,点击附件后要很长世间才弹出下载,请耐心等待,勿重复点击不要用Edge和IE浏览器下载,否则提示不安全下载不了

 找回密码
 立即注册
搜索
查看: 2073|回复: 0

[海外情报] Tor Browser Issues Update for Critical System Takeover Flaw

[复制链接]

该用户从未签到

10

主题

28

回帖

0

积分

二级逆天

积分
0

终身成就奖

发表于 2019-7-18 20:08:18 | 显示全部楼层 |阅读模式
from:https://www.bloomberg.com/news/a ... probably-filmed-you


Tor Browser Issues Update for Critical System Takeover Flaw


The update patches critical flaw (CVE-2019-11707), a type confusion vulnerability in the Mozilla Firefox code that Tor uses.


Tor Browser has updated to version 8.5.2, to address a critical security flaw in Mozilla’s Firefox browser that is under active exploit in the wild.
The critical flaw (CVE-2019-11707) is a type confusion vulnerability in the Array.pop, which is an array method that is used in JavaScript objects in Firefox. The vulnerability, which was disclosed and patched earlier this week, enables cybercriminals to take full control of systems running the vulnerable Firefox versions.
The issue affects Tor, since, as its founders said back in 2016, Firefox is at the heart of the privacy-focused onion browser.
[img]https://media.threatpost.com/wp-content/uploads/sites/103/2019/02/19

“If you’ve used Tor, you’ve probably used Tor Browser, and if you’ve used Tor Browser you’ve used Firefox,” they said [url=https://blog.torproject.org/tor-heart-firefox]in a posting
. “By lines of code, Tor Browser is mostly Firefox — there are some modifications and some additions, but around 95 percent of the code in Tor Browser comes from Firefox.”
The Android release for Tor won’t be available until this weekend, the project said, because of team travel.
“In the meantime, Android users should use the safer or safest security levels,” Tor said in an update on Thursday. “The security level on Android can be changed by going in the menu on the right of the URL bar and selecting Security Settings.”
Speedy updates are recommended given that the Firefox bug is being actively exploited in targeted attacks against Coinbase employees – and potentially other cryptocurrency organizations.
“On Monday, June 17, 2019, Coinbase reported a vulnerability used as part of targeted attacks for a spear phishing campaign,” Selena Deckelmann, senior director of Firefox Browser Engineering, told Threatpost. “In less than 24 hours, we released a fix for the exploit.”
Meanwhile, Tor also updated NoScript to 10.6.3, “fixing a few issues” – the update means that it no longer blocks MP4 on higher security levels, and it prevents cross-site scripting (XSS) protection from freezing the browser.
回复

使用道具 举报

您需要登录后才可以回帖 登录 | 立即注册

本版积分规则

论坛开启做任务可以
额外奖励金币快速赚
积分升级了


Copyright ©2011-2024 NTpcb.com All Right Reserved.  Powered by Discuz! (NTpcb)

本站信息均由会员发表,不代表NTpcb立场,如侵犯了您的权利请发帖投诉

平平安安
TOP
快速回复 返回顶部 返回列表