Lançado o Mozilla Firefox 90

A Mozilla anuncia o lançamento da versão 90 do navegador de internet Firefox, confira as novidades e correções de segurança.




Firefox


Mozilla Firefox é um navegador livre e multiplataforma desenvolvido pela Mozilla Foundation com ajuda de centenas de colaboradores. A intenção da fundação é desenvolver um navegador leve, seguro, intuitivo e altamente extensível. Wikipédia



Mozilla Firefox 90


O anúncio foi feito pela Mozilla em 13 de Julho de 2021.

 

"Versão 90.0, oferecida pela primeira vez aos usuários do canal de lançamento em 13 de julho de 2021

Gostaríamos de estender um agradecimento especial a todos os novos Mozillians que contribuíram para este lançamento do Firefox!"




Novidades


No Windows, as atualizações agora podem ser aplicadas em segundo plano enquanto o Firefox não está em execução.

O Firefox para Windows agora oferece uma nova página sobre: ​​terceiros para ajudar a identificar problemas de compatibilidade causados ​​por aplicativos de terceiros

Exceções ao modo HTTPS apenas podem ser gerenciadas em cerca de: preferências # privacidade

Imprimir em PDF agora produz hiperlinks funcionais

A versão 2 do recurso SmartBlock do Firefox melhora ainda mais a navegação privada. Os scripts do Facebook de terceiros são bloqueados para evitar que você seja rastreado, mas agora são carregados automaticamente “na hora certa” se você decidir “Entrar com o Facebook” em qualquer site.

Segurança

 

Além das novas implementações o Firefoz 90 recebe um bom pacote de correções que você pode conferir no quadro abaixo.



Mozilla Foundation Security Advisory 2021-28 Security Vulnerabilities fixed in Firefox 90 Announced July 13, 2021 Impact high Products Firefox Fixed in Firefox 90 #CVE-2021-29970: Use-after-free in accessibility features of a document Reporter Irvan Kurniawan Impact high Description A malicious webpage could have triggered a use-after-free, memory corruption, and a potentially exploitable crash. This bug only affected Firefox when accessibility was enabled. References Bug 1709976 #CVE-2021-29971: Granted permissions only compared host; omitting scheme and port on Android Reporter Arturo Mejia Impact high Description If a user had granted a permission to a webpage and saved that grant, any webpage running on the same host - irrespective of scheme or port - would be granted that permission. This bug only affects Firefox for Android. Other operating systems are unaffected. References Bug 1713638 #CVE-2021-30547: Out of bounds write in ANGLE Reporter (Unknown) Impact high Description An out of bounds write in ANGLE could have allowed an attacker to corrupt memory leading to a potentially exploitable crash. References Bug 1715766 #CVE-2021-29972: Use of out-of-date library included use-after-free vulnerability Reporter Irvan Kurniawan Impact moderate Description A user-after-free vulnerability was found via testing, and traced to an out-of-date Cairo library. Updating the library resolved the issue, and may have remediated other, unknown security vulnerabilities as well. References Bug 1696816 #CVE-2021-29973: Password autofill on HTTP websites was enabled without user interaction on Android Reporter Wladimir Palant working with Include Security Impact moderate Description Password autofill was enabled without user interaction on insecure websites on Firefox for Android. This was corrected to require user interaction with the page before a user's password would be entered by the browser's autofill functionality. This bug only affects Firefox for Android. Other operating systems are unaffected. References Bug 1701932 #CVE-2021-29974: HSTS errors could be overridden when network partitioning was enabled Reporter Peter Gerber Impact moderate Description When network partitioning was enabled, e.g. as a result of Enhanced Tracking Protection settings, a TLS error page would allow the user to override an error on a domain which had specified HTTP Strict Transport Security (which implies that the error should not be override-able.) This issue did not affect the network connections, and they were correctly upgraded to HTTPS automatically. References Bug 1704843 #CVE-2021-29975: Text message could be overlaid on top of another website Reporter Irvan Kurniawan Impact moderate Description Through a series of DOM manipulations, a message, over which the attacker had control of the text but not HTML or formatting, could be overlaid on top of another domain (with the new domain correctly shown in the address bar) resulting in possible user confusion. References Bug 1713259 #CVE-2021-29976: Memory safety bugs fixed in Firefox 90 and Firefox ESR 78.12 Reporter Mozilla developers Impact high Description Mozilla developers Emil Ghitta, Tyson Smith, Valentin Gosu, Olli Pettay, and Randell Jesup reported memory safety bugs present in Firefox 89 and Firefox ESR 78.11. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. References Memory safety bugs fixed in Firefox 90 and Firefox ESR 78.12 #CVE-2021-29977: Memory safety bugs fixed in Firefox 90 Reporter Mozilla developers Impact high Description Mozilla developers Andrew McCreight, Tyson Smith, Christian Holler, and Gabriele Svelto reported memory safety bugs present in Firefox 89. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. References Memory safety bugs fixed in Firefox 90


Fonte


Instalação

 

Se você já tem o Firefox instalado aguarde que a atualização ira chegar a ele em breve.

Se ainda não o tem instalado confira nossa matéria para ter um dos melhores navegadores de internet na sua distribuição de pacotes Linux.


Instalar Firefox sempre atualizado na sua distribuição GNU/Linux

O Debian vem com o Firefox-ESR instalado e só tem essa versão no repositório Stable, se você prefere o Firefox mais atual da Mozilla confira essa matéria.
O método pode ser usado em qualquer distribuição GNU/Linux.




Comentários

Você precisa ver isso

Todos os arquivos do blog

Mostrar mais