Mozilla Releases Firefox 66.0.1 to Patch Two Critical Security Vulnerabilities
#1
Exclamation 
Quote:Mozilla released the first point release to its latest Firefox 66 web browser to address two critical security vulnerabilities exposed during the Pwn2Own hacking contest event.

Firefox 66.0.1 is now available, just a few days after the release of Firefox 66.0 earlier this week, to patch CVE-2019-9810 and CVE-2019-9813, two security vulnerabilities reported by Richard Zhu, Amat Cama, and Niklas Baumstark via Trend Micro's Zero Day Initiative.
 
According to the security advisory published by Mozilla on March 22nd, CVE-2019-9810 describes a buffer overflow issue and missing bounds check flaw in the Firefox 66.0 release due to incorrect alias information in the IonMonkey JIT compiler for the Array.prototype.slice method.
 
On the other hand, CVE-2019-9813 describes a "type confusion" issue in the IonMonkey JIT code affecting the Firefox 66.0 release that may let attackers read and write arbitrary memory, which was possible due to incorrect handling of __proto__ mutations.

SOURCE: https://news.softpedia.com/news/mozilla-...5408.shtml
[-] The following 1 user says Thank You to silversurfer for this post:
  • harlan4096
Reply
#2
Additional info: https://www.ghacks.net/2019/03/23/mozill...0-6-1-esr/
[-] The following 1 user says Thank You to harlan4096 for this post:
  • silversurfer
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Mozilla Firefox Browser 148.0.2
Mozilla Firefox Br...harlan4096 — 10:28
QOwnNotes
26.3.6  Added a l...Kool — 10:28
AnyDesk Version 8.0.0 for Linux
AnyDesk Version 8....harlan4096 — 10:27
PrivaZer 4.0.119.1
PrivaZer 4.0.119.1...harlan4096 — 10:26
uBOLite 2026.308.1810 (already released ...
uBOLite 2026.308.1...harlan4096 — 10:26

[-]
Birthdays
Today's Birthdays
avatar (45)walllMIZ
avatar (41)oconyho
Upcoming Birthdays
avatar (44)gapedDow
avatar (38)snorydar
avatar (43)Hectorvot
avatar (51)knowhanPluts
avatar (39)Williamengiz
avatar (46)qaqapeti
avatar (44)battsourIonix
avatar (43)CedricSek
avatar (39)chasRex
avatar (33)uteluxix
avatar (47)piafcflene
avatar (39)Matthewkah
avatar (51)tersfargum
avatar (50)alfreExept
avatar (38)Charlesfibre
avatar (42)napasvem
avatar (44)diploJeoca
avatar (38)francisnj3
avatar (43)artmaGoork
avatar (41)RichardCisee
avatar (38)ykazawu

[-]
Online Staff
There are no staff members currently online.

>