顯示具有 firefox 標籤的文章。 顯示所有文章
顯示具有 firefox 標籤的文章。 顯示所有文章

2020年11月7日 星期六

[USN-4599-1] Firefox vulnerabilities

 ---------- Forwarded message ---------

From: Chris Coulson <chris.coulson@canonical.com>

Date: Oct 23, 2020 7:33PM

Multiple security issues were discovered in Firefox. If a user were

tricked in to opening a specially crafted website, an attacker could

potentially exploit these to cause a denial of service, spoof the prompt

for opening an external application, obtain sensitive information, or

execute arbitrary code.

References:

  https://usn.ubuntu.com/4599-1

  CVE-2020-15254, CVE-2020-15680, CVE-2020-15681, CVE-2020-15682,

  CVE-2020-15683, CVE-2020-15684, CVE-2020-15969

2020年10月25日 星期日

[USN-4546-1] Firefox vulnerabilities

 ---------- Forwarded message ---------

From: Chris Coulson <chris.coulson@canonical.com>

Date: Sep 28, 2020 5:47PM

Multiple security issues were discovered in Firefox. If a user were

tricked in to opening a specially crafted website, an attacker could

potentially exploit these to cause a denial of service, conduct cross-site

scripting (XSS) attacks, spoof the site displayed in the download dialog,

or execute arbitrary code.

References:

  https://usn.ubuntu.com/4546-1

  CVE-2020-15673, CVE-2020-15674, CVE-2020-15675, CVE-2020-15676,

  CVE-2020-15677, CVE-2020-15678

2020年9月15日 星期二

[USN-4474-1] Firefox vulnerabilities

 ---------- Forwarded message ---------

From: Chris Coulson <chris.coulson@canonical.com>

Date: Aug 27, 2020 3:03AM

Multiple security issues were discovered in Firefox. If a user were

tricked in to opening a specially crafted website, an attacker could

potentially exploit these to cause a denial of service, trick the user

in to installing a malicious extension, spoof the URL bar, leak sensitive

information between origins, or execute arbitrary code. (CVE-2020-15664,

CVE-2020-15665, CVE-2020-15666, CVE-2020-15670)

It was discovered that NSS incorrectly handled certain signatures.

An attacker could possibly use this issue to expose sensitive information.

(CVE-2020-12400, CVE-2020-12401, CVE-2020-6829)

A data race was discovered when importing certificate information in to

the trust store. An attacker could potentially exploit this to cause an

unspecified impact. (CVE-2020-15668)

References:

  https://usn.ubuntu.com/4474-1

  CVE-2020-12400, CVE-2020-12401, CVE-2020-15664, CVE-2020-15665,

  CVE-2020-15666, CVE-2020-15668, CVE-2020-15670, CVE-2020-6829

2020年8月16日 星期日

[USN-4443-1] Firefox vulnerabilities

 ---------- Forwarded message ---------

From: Chris Coulson <chris.coulson@canonical.com>

Date: Jul 30, 2020 3:36AM

Multiple security issues were discovered in Firefox. If a user were

tricked in to opening a specially crafted website, an attacker could

potentially exploit these to cause a denial of service, obtain sensitive

information, bypass iframe sandbox restrictions, confuse the user, or

execute arbitrary code. (CVE-2020-6463, CVE-2020-6514, CVE-2020-15652,

CVE-2020-15653, CVE-2020-15654, CVE-2020-15656, CVE-2020-15658,

CVE-2020-15659)

It was discovered that redirected HTTP requests which are observed or

modified through a web extension could bypass existing CORS checks. If a

user were tricked in to installing a specially crafted extension, an

attacker could potentially exploit this to obtain sensitive information

across origins. (CVE-2020-15655)

References:

  https://usn.ubuntu.com/4443-1

  CVE-2020-15652, CVE-2020-15653, CVE-2020-15654, CVE-2020-15655,

  CVE-2020-15656, CVE-2020-15658, CVE-2020-15659, CVE-2020-6463,

  CVE-2020-6514

2020年6月27日 星期六

[USN-4383-1] Firefox vulnerabilities

---------- Forwarded message ---------
From: Chris Coulson <chris.coulson@canonical.com>
Date: Jun 5, 2020 4:58AM

Multiple security issues were discovered in Firefox. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service, spoof the
addressbar, or execute arbitrary code. (CVE-2020-12405, CVE-2020-12406,
CVE-2020-12407, CVE-2020-12408, CVE-2020-12409, CVE-2020-12410,
CVE-2020-12411)

It was discovered that NSS showed timing differences when performing DSA
signatures. An attacker could potentially exploit this to obtain private
keys using a timing attack. (CVE-2020-12399)

References:
  https://usn.ubuntu.com/4383-1
  CVE-2020-12399, CVE-2020-12405, CVE-2020-12406, CVE-2020-12407,
  CVE-2020-12408, CVE-2020-12409, CVE-2020-12410, CVE-2020-12411

2020年5月23日 星期六

[USN-4353-1] Firefox vulnerabilities

---------- Forwarded message ---------
From: Chris Coulson
Date: May 7, 2020 11:18PM

Multiple security issues were discovered in Firefox. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to cause a denial of service, bypass security
restrictions, spoof the URL bar, or execute arbitrary code.
(CVE-2020-6831, CVE-2020-12387, CVE-2020-12390, CVE-2020-12391,
CVE-2020-12394, CVE-2020-12395, CVE-2020-12396)

It was discovered that the Devtools’ ‘Copy as cURL’ feature did not
properly HTTP POST data of a request. If a user were tricked in to using
the ‘Copy as cURL’ feature to copy and paste a command with specially
crafted data in to a terminal, an attacker could potentially exploit this
to obtain sensitive information from local files.
(CVE-2020-12392)

References:
  https://usn.ubuntu.com/4353-1
  CVE-2020-12387, CVE-2020-12390, CVE-2020-12391, CVE-2020-12392,
  CVE-2020-12394, CVE-2020-12395, CVE-2020-12396, CVE-2020-6831

2020年4月11日 星期六

[USN-4317-1] Firefox vulnerabilities

---------- Forwarded message ---------
From: Chris Coulson
Date: Apr 4, 2020 9:41PM

Two use-after-free bugs were discovered in Firefox. If a user were tricked
in to opening a specially crafted website, an attacker could exploit these
to cause a denial of service or execute arbitrary code.fi

References:
  https://usn.ubuntu.com/4317-1
  CVE-2020-6819, CVE-2020-6820

2019年10月1日 星期二

[USN-4140-1] Firefox vulnerability

---------- Forwarded message ---------
From: Chris Coulson
Date: Sep 26, 2019 6:58AM

It was discovered that no user notification was given when pointer lock is
enabled. If a user were tricked in to opening a specially crafted website,
an attacker could potentially exploit this to hijack the mouse pointer and
confuse users.

References:
  https://usn.ubuntu.com/4140-1
  CVE-2019-11754

2019年9月30日 星期一

[USN-4122-1] Firefox vulnerabilities

---------- Forwarded message ---------
From: Chris Coulson
Date: Sep 5, 2019 5:50AM

Multiple security issues were discovered in Firefox. If a user were
tricked in to opening a specially crafted website, an attacker could
potentially exploit these to obtain sensitive information, bypass
Content Security Policy (CSP) protections, bypass same-origin
restrictions, conduct cross-site scripting (XSS) attacks, cause a denial
of service, or execute arbitrary code. (CVE-2019-5849, CVE-2019-11734,
CVE-2019-11735, CVE-2019-11737, CVE-2019-11738, CVE-2019-11740,
CVE-2019-11742, CVE-2019-11743, CVE-2019-11744, CVE-2019-11746,
CVE-2019-11748, CVE-2019-11749, CVE-2019-11750, CVE-2019-11752)

It was discovered that a compromised content process could log in to a
malicious Firefox Sync account. An attacker could potentially exploit
this, in combination with another vulnerability, to disable the sandbox.
(CVE-2019-9812)

It was discovered that addons.mozilla.org and accounts.firefox.com could
be loaded in to the same content process. An attacker could potentially
exploit this, in combination with another vulnerability that allowed a
cross-site scripting (XSS) attack, to modify browser settings.
(CVE-2019-11741)

It was discovered that the "Forget about this site" feature in the
history pane removes HTTP Strict Transport Security (HSTS) settings for
sites on the pre-load list. An attacker could potentially exploit this
to bypass the protections offered by HSTS. (CVE-2019-11747)

References:
  https://usn.ubuntu.com/4122-1
  CVE-2019-11734, CVE-2019-11735, CVE-2019-11737, CVE-2019-11738,
  CVE-2019-11740, CVE-2019-11741, CVE-2019-11742, CVE-2019-11743,
  CVE-2019-11744, CVE-2019-11746, CVE-2019-11747, CVE-2019-11748,
  CVE-2019-11749, CVE-2019-11750, CVE-2019-11752, CVE-2019-5849,
  CVE-2019-9812

2018年12月28日 星期五

Firefox 63.0 was released.

63.0

Firefox Release

October 23, 2018

Version 63.0, first offered to Release channel users on October 23, 2018

...users can opt to block third-party tracking cookies or block all trackers and create exceptions for trusted sites that don't work correctly with content blocking enabled.
REF: https://www.mozilla.org/en-US/firefox/63.0/releasenotes/

2018年3月25日 星期日

USN-3596-1: Firefox vulnerabilities

It was discovered that the value of app.support.baseURL is not sanitized properly. If a malicious local application were to set this to a specially crafted value, an attacker could potentially exploit this to execute arbitrary code. (CVE-2018-5133)
It was discovered that javascript: URLs with embedded tab characters could be pasted in to the addressbar. If a user were tricked in to copying a specially crafted URL in to the addressbar, an attacker could exploit this to conduct cross-site scripting (XSS) attacks. (CVE-2018-5143)
REF: https://usn.ubuntu.com/3596-1/

2018年3月13日 星期二

Firefox 57 “Quantum”, Faster and Higher

The new Firefox is described as twice as fast as the version released a year ago, with a 30 percent savings in memory usage. In addition, Firefox 57 is supposed to be as fast as Google Chrome.

REF: http://www.linux-magazine.com/Issues/2018/209/Web-Performance

2017年12月14日 星期四

The many ways of running firefox on OpenBSD

First, and this has been the case for a few years already, these days I only target amd64 and i386. It's been "fun" for a while but now it's impossible to keep up with macppc and sparc64, although Martin Husemann from NetBSD still manages to run recent firefox on sparc64, i gave up on this - even *running* firefox on an i386 netbook with 1Gb of memory is unbearable. Sad state of affairs.. and on top of this, the recent dependency on rust also limits the amount of platforms firefox could run on, since rust only works on amd64 and i386 for now (thanks to the insane amount of work by semarie@ !).

REF: https://undeadly.org/cgi?action=article&sid=20170425173917

2017年11月10日 星期五

Mozilla adds multiprocessing with Electrolysis in Firefox 54

REF: http://www.linux-magazine.com/Issues/2017/204/Firefox-54-with-Electrolysis

Developers are praising Firefox 54 as the "best Firefox ever." The revamped web browser adds multiprocessing and promises a significant boost in speed.

2012年1月24日 星期二

java plugin for firefox on Linux

http://java.com/zh_TW/download/help/linux_install.xml

0. check firefox url -- about:plugins.
1. install java from java.com
2. soft link the libnpjp2.so to firefox plugins folder, e.g. /usr/lib/mozilla/plugins.
$ sudo ln -s /usr/local/jre1.6.0_30/lib/i386/libnpjp2.so .
3. restart firefox, and everything's done!!