출처: http://la-nube.tistory.com/351 [la Nube's Lab. | 라 누베 연구소]
모질라(Mozilla)에서
개발하는 웹브라우저 '불여우' 파이어폭스(Firefox)의 새로운 기능 추가나 버그 수정 또는 보안 취약점 문제를 해결한
파이어폭스 59.0 버전이 윈도, 맥OS, 리눅스에서 업데이트를 통해 각각 배포되었습니다.
--
이번 업데이트에는 다음과 같은 18건의 보안 취약점에 대한 보안 패치가 포함되어 있습니다.
■ Critical 등급 (2)
CVE-2018-5126: Memory safety bugs fixed in Firefox 59
CVE-2018-5125: Memory safety bugs fixed in Firefox 59 and Firefox ESR 52.7
■ High 등급 (4)
CVE-2018-5127: Buffer overflow manipulating SVG animatedPathSegList
CVE-2018-5128: Use-after-free manipulating editor selection ranges
CVE-2018-5129: Out-of-bounds write with malformed IPC messages
CVE-2018-5130: Mismatched RTP payload type can trigger memory corruption
■ Moderate 등급 (7)
CVE-2018-5131: Fetch API improperly returns cached copies of no-store/no-cache resources
CVE-2018-5132: WebExtension Find API can search privileged pages
CVE-2018-5133: Value of the app.support.baseURL preference is not properly sanitized
CVE-2018-5134: WebExtensions may use view-source: URLs to bypass content restrictions
CVE-2018-5135: WebExtension browserAction can inject scripts into unintended contexts
CVE-2018-5136: Same-origin policy violation with data: URL shared workers
CVE-2018-5137: Script content can access legacy extension non-contentaccessible resources
■ Low 등급 (5)
CVE-2018-5138: Android Custom Tab address spoofing through long domain names
CVE-2018-5140: Moz-icon images accessible to web content through moz-icon: protocol
CVE-2018-5141: DOS attack through notifications Push API
CVE-2018-5142: Media Capture and Streams API permissions display incorrect origin with data: and blob: URLs
CVE-2018-5143: Self-XSS pasting javascript: URL with embedded tab into addressbar
--
그 외에 다음과 같은 새로운 기능 추가 또는 버그 수정이 이루어졌습니다.
■ NEW - Performance improvements
* Faster load times for content on the Firefox Home page
* Faster page load times by loading either from the networked cache or
the cache on the user’s hard drive (Race Cache With Network)
*
Improved graphics rendering using Off-Main-Thread Painting (OMTP) for
Mac users (OMTP for Windows was released in Firefox 58)
■ NEW - Drag-and-drop to rearrange Top Sites on the Firefox Home page, and customize new windows and tabs in other ways
■ NEW - Added features for Firefox Screenshots:
* Basic annotation lets the user draw on and highlight saved screenshots
* Recropping to change the viewable area of saved screenshots
■
NEW - Enhanced WebExtensions API including better support for
decentralized protocols and the ability to dynamically register content
scripts
■ NEW - Improved Real-Time Communications (RTC) capabilities.
* Implemented RTP Transceiver to give pages more fine grained control over calls
* Implemented features to support large scale conferences
■
NEW - Added support for W3C specs for pointer events and improved
platform integration with added device support for mouse, pen, and touch
screen pointer input
■ NEW - Added the Ecosia search engine as an option for German Firefox
■ NEW - Added the Qwant search engine as an option for French Firefox
■
NEW - Added settings in about:preferences to stop websites from asking
to send notifications or access your device’s camera, microphone, and
location, while still allowing trusted websites to use these features
■ CHANGED - Firefox Private Browsing Mode will remove path information from referrers to prevent cross-site tracking
자세한 업데이트 내역은 아래 링크의 정보를 참고하기 바랍니다.
--
[영향을 받는 소프트웨어 및 업데이트 버전]
□ 파이어폭스 58.0.2 및 이하 버전 → 파이어폭스 59.0 버전으로 업데이트
※ https://www.mozilla.org/en-US/firefox/59.0/releasenotes/
※ https://www.mozilla.org/en-US/security/advisories/mfsa2018-06/
--
그러므로 파이어폭스 사용자는 자동 업데이트('메뉴 열기 → 도움말 → Firefox 정보') 기능을 통해 최신버전으로 업데이트하기 바랍니다.
리눅스에서는 패키지 업데이트를 통해 최신버전으로 업데이트하기 바랍니다.
데비안 / 우분투 기준 : $ sudo apt-get update && sudo apt-get dist-upgrade
출처: http://la-nube.tistory.com/351 [la Nube's Lab. | 라 누베 연구소]
소식글 잘 봤습니다
파이어폭스가 새 엔진을 기반으로 다시 당차게 앞으로나아가길