Vhiki rino, musi wa19, Mozilla yakaburitsa huru yekuvandudza yebrowser yayo. Mazuva mashoma gare gare, iyo nyowani vhezheni yakasvika kumahofisi epamutemo uye nhasi, mazuva maviri gare gare, kambani yave yakaburitsa Firefox 66.0.1, vhezheni inouya kuzogadzirisa zvikanganiso zviviri zvakakosha zvekuchengetedza izvo zvakawanikwa mumakwikwi ePwn2Own ekupaza, uko kwavakazvipira kutsvaga nekushandisa mhando idzi dzezvikanganiso, asi zvakatinakira.
Firefox 66.0.1 iri inowanikwa yeWindows, Mac uye Linux, asi haisati yawanikwa senge snap package kana mumabhuku epamutemo. Tichifunga nezvekuti zvakatora nguva yakadii kuti v66 isvike, tinogona kufunga kuti v66.0.1 ichave iripo Muvhuro unotevera. Ichi ndicho CHINODA mapapiro ekutsvaira kana mamwe mapakeji akafanana akadai seFlatpak akakosha zvakanyanya: kunyangwe zvisingaonekwe muiyo Snappy Chitoro parizvino, iyo snap package inogamuchira zvigadziriso kuburikidza nePush, kureva kuti, chirongwa chimwe chete chinovagamuchira pavanongovhurwa.
Firefox 66.0.1 iri kuuya nekukurumidza kunzvimbo dzepamutemo
ari bugs iyo iyi vhezheni inogadzirisa Iwo ari CVE-2019-9810 uye CVE-2019-9813, ese akawanikwa naRichard Zhu, Amat Cama, naNiklas Baumstark kuburikidza neTrend Micro's Zero Day Initiative. Yekutanga yeiri inotsanangura a buffer zadzisa dambudziko uye muganho cheki kutadza ndisipo muFirefox 66 nekuda kwemashoko asiri iwo muIonMonkey JIT compiler yeArray.prototype.slice nzira.
Kune rimwe divi, iyo CVE-2019-9813 iri pamusoro dambudziko re "typing confusion" muIonMonkey JIT pachayo, asi panguva ino mune kodhi. Iyi bhagi inogona kubvumira mushandisi akaipa kuti averenge nekunyora ndangariro dzinopesana, iyo yaive (uye ichiri kugoneka muv66) inogoneka nekuda kwekusabatwa zvakanaka kwe__proto__mutations.
Mozilla inokurudzira vese vashandisi kugadzirisa zvakanyanya sezvinobvira. Sezvatakambotaura, vashandisi veWindows uye macOS vanozokwanisa kuzviita kubva kunyevero inoratidzwa neFirefox apo inogadziridza iripo nekuda kwekuti Push inogadziridza yagara iripo pane iwo masisitimu. Vashandisi veLinux vanogona dhawunorodha vhezheni itsva uye ita iyo yekuisa yekuisa, asi haisi iyo yakanyanya kukurudzirwa. Avo vari kushandisa iyo snap package vanozokwanisa kugadzirisa izvozvi, nepo isu vedu vanoshandisa iyo APT vhezheni vachazofanira kumirira mazuva akati wandei. Ngatimirirei ipapo.
Iva wekutanga kutaura