A Mozilla anuncia o lançamento da versão 90 do navegador de internet Firefox, confira as novidades e correções de segurança.
Firefox
Mozilla Firefox é um navegador livre e multiplataforma desenvolvido pela Mozilla Foundation com ajuda de centenas de colaboradores. A intenção da fundação é desenvolver um navegador leve, seguro, intuitivo e altamente extensível. Wikipédia
Mozilla Firefox 90
O anúncio foi feito pela Mozilla em 13 de Julho de 2021.
"Versão 90.0, oferecida pela primeira vez aos usuários do canal de lançamento em 13 de julho de 2021
Gostaríamos de estender um agradecimento especial a todos os novos Mozillians que contribuíram para este lançamento do Firefox!"
Novidades
No Windows, as atualizações agora podem ser aplicadas em segundo plano enquanto o Firefox não está em execução.
O Firefox para Windows agora oferece uma nova página sobre: terceiros para ajudar a identificar problemas de compatibilidade causados por aplicativos de terceiros
Exceções ao modo HTTPS apenas podem ser gerenciadas em cerca de: preferências # privacidade
Imprimir em PDF agora produz hiperlinks funcionais
A versão 2 do recurso SmartBlock do Firefox melhora ainda mais a navegação privada. Os scripts do Facebook de terceiros são bloqueados para evitar que você seja rastreado, mas agora são carregados automaticamente “na hora certa” se você decidir “Entrar com o Facebook” em qualquer site.
Segurança
Além das novas implementações o Firefoz 90 recebe um bom pacote de correções que você pode conferir no quadro abaixo.
Mozilla Foundation Security Advisory 2021-28
Security Vulnerabilities fixed in Firefox 90
Announced
July 13, 2021
Impact
high
Products
Firefox
Fixed in
Firefox 90
#CVE-2021-29970: Use-after-free in accessibility features of a document
Reporter
Irvan Kurniawan
Impact
high
Description
A malicious webpage could have triggered a use-after-free, memory corruption, and a potentially exploitable crash.
This bug only affected Firefox when accessibility was enabled.
References
Bug 1709976
#CVE-2021-29971: Granted permissions only compared host; omitting scheme and port on Android
Reporter
Arturo Mejia
Impact
high
Description
If a user had granted a permission to a webpage and saved that grant, any webpage running on the same host - irrespective of scheme or port - would be granted that permission.
This bug only affects Firefox for Android. Other operating systems are unaffected.
References
Bug 1713638
#CVE-2021-30547: Out of bounds write in ANGLE
Reporter
(Unknown)
Impact
high
Description
An out of bounds write in ANGLE could have allowed an attacker to corrupt memory leading to a potentially exploitable crash.
References
Bug 1715766
#CVE-2021-29972: Use of out-of-date library included use-after-free vulnerability
Reporter
Irvan Kurniawan
Impact
moderate
Description
A user-after-free vulnerability was found via testing, and traced to an out-of-date Cairo library. Updating the library resolved the issue, and may have remediated other, unknown security vulnerabilities as well.
References
Bug 1696816
#CVE-2021-29973: Password autofill on HTTP websites was enabled without user interaction on Android
Reporter
Wladimir Palant working with Include Security
Impact
moderate
Description
Password autofill was enabled without user interaction on insecure websites on Firefox for Android. This was corrected to require user interaction with the page before a user's password would be entered by the browser's autofill functionality.
This bug only affects Firefox for Android. Other operating systems are unaffected.
References
Bug 1701932
#CVE-2021-29974: HSTS errors could be overridden when network partitioning was enabled
Reporter
Peter Gerber
Impact
moderate
Description
When network partitioning was enabled, e.g. as a result of Enhanced Tracking Protection settings, a TLS error page would allow the user to override an error on a domain which had specified HTTP Strict Transport Security (which implies that the error should not be override-able.) This issue did not affect the network connections, and they were correctly upgraded to HTTPS automatically.
References
Bug 1704843
#CVE-2021-29975: Text message could be overlaid on top of another website
Reporter
Irvan Kurniawan
Impact
moderate
Description
Through a series of DOM manipulations, a message, over which the attacker had control of the text but not HTML or formatting, could be overlaid on top of another domain (with the new domain correctly shown in the address bar) resulting in possible user confusion.
References
Bug 1713259
#CVE-2021-29976: Memory safety bugs fixed in Firefox 90 and Firefox ESR 78.12
Reporter
Mozilla developers
Impact
high
Description
Mozilla developers Emil Ghitta, Tyson Smith, Valentin Gosu, Olli Pettay, and Randell Jesup reported memory safety bugs present in Firefox 89 and Firefox ESR 78.11. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.
References
Memory safety bugs fixed in Firefox 90 and Firefox ESR 78.12
#CVE-2021-29977: Memory safety bugs fixed in Firefox 90
Reporter
Mozilla developers
Impact
high
Description
Mozilla developers Andrew McCreight, Tyson Smith, Christian Holler, and Gabriele Svelto reported memory safety bugs present in Firefox 89. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code.
References
Memory safety bugs fixed in Firefox 90
Fonte
Instalação
Se você já tem o Firefox instalado aguarde que a atualização ira chegar a ele em breve.
Se ainda não o tem instalado confira nossa matéria para ter um dos melhores navegadores de internet na sua distribuição de pacotes Linux.
O
Debian vem com o Firefox-ESR instalado e só tem essa versão no
repositório Stable, se você prefere o Firefox mais atual da Mozilla
confira essa matéria.
O método pode ser usado em qualquer distribuição GNU/Linux.
Comentários
Postar um comentário
olá, seja bem vindo ao Linux Dicas e suporte !!