Tor Browser 8.5.2 Released — Update to Fix Critical Firefox Vulnerability
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2019-11707 | Type Confusion in Mozilla Firefox and Thunderbird JavaScript Engine Mozilla Firefox and Thunderbird contain a type confusion flaw (CWE-843) in the JavaScript engine's Array.pop handling, which occurs when manipulating JavaScript objects and can lead to an exploitable crash. An attacker can trigger it by getting a user to load crafted web or email content that executes the malicious JavaScript, gaining a crash that is exploitable (typically escalating to arbitrary code execution in the browser or mail client context). All users of the affected Firefox and Thunderbird builds are exposed, since both products process untrusted web and HTML email content. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-05-23), indicating known in-the-wild exploitation, and it carries a high EPSS of 37.7% (98th percentile); no public proof-of-concept is cataloged and CVSS has not yet been scored. Do: Apply updates per Mozilla's instructions, as required by the CISA KEV catalog: upgrade Firefox and Thunderbird to the latest supported releases and verify the installed version via the About dialog. Because the flaw dates to 2019, any fully updated auto-updating installation is already protected; audit for stale or unmanaged Firefox/Thunderbird deployments, and as an interim mitigation minimize JavaScript execution from untrusted web and email content. | 8.8 | 38% | KEV |
| masshundreds of millions of users in the potential base (Firefox install base plus tens of millions of Thunderbird installs), though currently unpatched installs… |
Full article334 words · extracted from thehackernews.com · click to collapse
The Hacker NewsJun 20, 2019
Important Update (21 June 2019) ➤ The Tor Project on Friday released second update (Tor Browser 8.5.3) for its privacy web-browser that patches the another Firefox zero-day vulnerability patched this week.
Following the latest critical update for Firefox, the Tor Project today released an updated version of its anonymity and privacy browser to patch the same Firefox vulnerability in its bundle.
Earlier this week, Mozilla released Firefox 67.0.3 and Firefox ESR 60.7.1 versions to patch a critical actively-exploited vulnerability (CVE-2019-11707) that could allow attackers to remotely take full control over systems running the vulnerable browser versions.
Besides updating Firefox, the latest Tor Browser 8.5.2 for desktops also includes updated NoScript version 10.6.3 that fixes a few known issues.
According to the Tor Project Team, if you are already using Tor browser with "safer" and "safest" security levels, the flaw doesn't affect you.
For some reason, the team hasn't yet released an updated Tor version for Android users, which should be available anytime soon in the next few days. However, Android users have been advised to switch on "safer" or "safest" security levels in order to mitigate the issue until a patched app becomes available.
"The security level on Android can be changed by going in the menu on the right of the URL bar and selecting Security Settings," Nicolas Vigier, the Lead Automation Engineer at Tor Project said.
The Google security researcher who discovered this flaw also revealed that it could be abused to launch universal cross-site scripting (UXSS) attacks as well, allowing malicious websites to bypass same-origin policy on the victim's web browser and steal sensitive information.
Since Tor is primarily being used by privacy-conscious users who can't afford to get compromised at any cost, it's highly recommended for them to install the latest version of the anonymity software immediately.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2019/06/tor-browser-firefox-hack.html