꿈을꾸는 파랑새

오늘은 모질라 재단에서 제공을 하는 브라우저인 파이어폭스 63(Firefox 63) 보안 업데이트에 대한 보안 업데이트가 진행이 되었습니다.
CVE-2018-12391: HTTP Live Stream audio data is accessible cross-origin
During HTTP Live Stream playback on Firefox for Android, audio data can be accessed across origins in violation of security policies. Because the problem is in the underlying Android service, this issue is addressed by treating all HLS streams as cross-origin and opaque to access.
Note: this issue only affects Firefox for Android. Desktop versions of Firefox are unaffected.
CVE-2018-12392: Crash with nested event loops
Description:When manipulating user events in nested loops while opening a document through script, it is possible to trigger a potentially exploitable crash due to poor event handling.
CVE-2018-12393: Integer overflow during Unicode conversion while loading JavaScript
Description:A potential vulnerability was found in 32-bit builds where an integer overflow during the conversion of scripts to an internal UTF-16 representation could result in allocating a buffer too small for the conversion. This leads to a possible out-of-bounds write.
Note: 64-bit builds are not vulnerable to this issue.

CVE-2018-12395: WebExtension bypass of domain restrictions through header rewriting
Description:By rewriting the Host request headers using the webRequest API, a WebExtension can bypass domain restrictions through domain fronting. This would allow access to domains that share a host that are otherwise restricted.
References
CVE-2018-12396: WebExtension content scripts can execute in disallowed contexts
Description:A vulnerability where a WebExtension can run content scripts in disallowed contexts following navigation or other events. This allows for potential privilege escalation by the WebExtension on sites where content scripts should not be run.
CVE-2018-12397:
Description:A WebExtension can request access to local files without the warning prompt stating that the extension will "Access your data for all websites" being displayed to the user. This allows extensions to run content scripts in local pages without permission warnings when a local file is opened.
CVE-2018-12398: CSP bypass through stylesheet injection in resource URIs
Description:By using the reflected URL in some special resource URIs, such as chrome:, it is possible to inject stylesheets and bypass Content Security Policy (CSP).
References
CVE-2018-12399: Spoofing of protocol registration notification bar
Description:When a new protocol handler is registered, the API accepts a title argument which can be used to mislead users about which domain is registering the new protocol. This may result in the user approving a protocol handler that they otherwise would not have.
References
CVE-2018-12400: Favicons are cached in private browsing mode on Firefox for Android
Description:In private browsing mode on Firefox for Android, favicons are cached in the cache/icons folder as they are in non-private mode. This allows information leakage of sites visited during private browsing sessions.
Note: this issue only affects Firefox for Android. Desktop versions of Firefox are unaffected.
CVE-2018-12401: DOS attack through special resource URI parsing
Some special resource URIs will cause a non-exploitable crash if loaded with optional parameters following a '?' in the parsed string. This could lead to denial of service (DOS) attacks.
CVE-2018-12402: SameSite cookies leak when pages are explicitly saved
SameSite cookies are sent on cross-origin requests when the "Save Page As..." menu item is selected to save a page, violating cookie policy. This can result in saving the wrong version of resources based on those cookies.
CVE-2018-12403: Mixed content warning is not displayed when HTTPS page loads a favicon over HTTP
Description:If a site is loaded over a HTTPS connection but loads a favicon resource over HTTP, the mixed content warning is not displayed to users.
CVE-2018-12388: Memory safety bugs fixed in Firefox 63
Description:Mozilla developers and community members Christian Holler, Dana Keeler, Ronald Crane, Marcia Knous, Tyson Smith, Daniel Veditz, and Steve Fink reported memory safety bugs present in Firefox 62. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code.
Memory safety bugs fixed in Firefox 63
CVE-2018-12390: Memory safety bugs fixed in Firefox 63 and Firefox ESR 60.3
Description:Mozilla developers and community members Christian Holler, Bob Owen, Boris Zbarsky, Calixte Denizet, Jason Kratzer, Jed Davis, Taegeon Lee, Philipp, Ronald Crane, Raul Gurzau, Gary Kwong, Tyson Smith, Raymond Forbes, and Bogdan Tara reported memory safety bugs present in Firefox 62 and Firefox ESR 60.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code
입니다. 일단 기본적으로 파이어폭스를 사용하시는 분들은 반드시 보안업데이트가 진행이 돼야 합니다. 그리고 파이어폭스 63(Firefox 63) 안드로이드 버전에서는 한국어에서는 아직도 한국어가 제대로 글자가 적혀지지 않고 있습니다. 일단 임시 방법은 구글 키보드 등을 설치하고 해당 안드로이드 키보드를 사용하시길 바랍니다. 그리고 이번 버전부터는 파이어폭스 자동 업데이트를 완전히 끄는 것을 차단해서 기본적으로 자동으로 업데이트를 하거나 최신 파이어폭스가 있으면 알려주는 기능만 존재하게 되었습니다. 해당 부분은 아마도 일부 사용자분들 중에서 업데이트를 하지 않는 분들에게 보안을 위해서 최신 업데이트를 하려고 자동업데이트 기능 끄는 부분을 없앤 것 같습니다.

글 공유하기 및 아이허브 추천 코드

페이스북
트위터
네이버
밴드
카톡
카스

댓글 보기

  1. Favicon of https://jongamk.tistory.com 핑구야 날자 2018.10.25 06:49 신고

    사용하시는 분들은 업데이트 확인해 봐야겠네요

    • Favicon of https://wezard4u.tistory.com Sakai 2018.10.25 17:39 신고

      보안 업데이트는 반드시 해야 된다고 생각을 합니다.보안을 위해서 이죠

  2. Favicon of https://deborah.tistory.com Deborah 2018.10.26 08:32 신고

    네 잘 보고 있습니다. 조심하고 보안에 대한 경각심을 알려주네요.