{"id":19477,"date":"2022-06-30T06:10:19","date_gmt":"2022-06-30T14:10:19","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2022\/06\/30\/news-13210\/"},"modified":"2022-06-30T06:10:19","modified_gmt":"2022-06-30T14:10:19","slug":"news-13210","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2022\/06\/30\/news-13210\/","title":{"rendered":"Update now! Mozilla fixes security vulnerabilities and introduces a new privacy feature for Firefox"},"content":{"rendered":"<p><strong>Credit to Author: Pieter Arntz| Date: Thu, 30 Jun 2022 14:01:41 +0000<\/strong><\/p>\n<p>Mozilla <a href=\"https:\/\/www.mozilla.org\/en-US\/firefox\/102.0\/releasenotes\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">released<\/a> version 102.0 of the Firefox browser to Release channel users on June 28, 2022.<\/p>\n<p>The new version fixes 20 security vulnerabilities, five of which are classified as \u201cHigh\u201d. The new version also comes with a new privacy feature that strips parameters from URLs that track you around the web.<\/p>\n<h2>Vulnerabilities<\/h2>\n<p>Publicly disclosed computer security flaws are listed in the Common Vulnerabilities and Exposures (CVE) database. Its goal is to make it easier to share data across separate vulnerability capabilities (tools, databases, and services). These are the CVEs we think you should know:<\/p>\n<h3>High<\/h3>\n<p><a href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2022-34479\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">CVE-2022-34479<\/a>: A malicious website that could create a popup could have resized the popup to overlay the address bar with its own content, resulting in potential user confusion or spoofing attacks. This bug only affects Firefox for Linux. It does not apply to other operating systems.<\/p>\n<p><a href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2022-34470\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">CVE-2022-34470<\/a>: Use-after-free in nsSHistory. Use after free (UAF) is a vulnerability caused by incorrect use of dynamic memory during a program&#8217;s operation. If after freeing a memory location, a program does not clear the pointer to that memory, an attacker can use the error to manipulate the program. Navigations between XML documents may have led to a use-after-free and potentially exploitable crash.<\/p>\n<p><a href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2022-34468\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">CVE-2022-34468<\/a>: CSP sandbox header without &#8216;allow-scripts&#8217; can be bypassed via retargeted javascript: URI. An iframe that was not permitted to run scripts could do so if the user clicked on a javascript: link.<\/p>\n<p><a href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2022-34484\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">CVE-2022-34484<\/a>: Memory safety bugs fixed in Firefox 102 and Firefox ESR 91.11. Some of these bugs showed evidence of JavaScript prototype or memory corruption, and with enough effort some of these could have been exploited to run arbitrary code.<\/p>\n<h3>Moderate<\/h3>\n<p><a href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2022-34482\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">CVE-2022-34482<\/a> and <a href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2022-34483\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">CVE-2022-34483<\/a>: Two separate issues with the same effect. Drag and drop of malicious image could have led to malicious executable and potential code execution. An attacker who could have convinced a user to drag and drop an image to a filesystem could have manipulated the resulting filename to contain an executable extension.<\/p>\n<p><a href=\"https:\/\/cve.mitre.org\/cgi-bin\/cvename.cgi?name=CVE-2022-34478\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">CVE-2022-34478<\/a>: The <a href=\"https:\/\/blog.malwarebytes.com\/exploits-and-vulnerabilities\/2022\/05\/microsoft-office-zero-day-follina-its-not-a-bug-its-a-feature-its-a-bug\/\">ms-msdt<\/a>, search, and search-ms protocols deliver content to Microsoft applications, bypassing the browser when a user accepts a prompt. These applications have had known vulnerabilities, exploited in the wild, so in this release Firefox has blocked these protocols from prompting the user to open them.<\/p>\n<h2>New privacy feature<\/h2>\n<p>Many companies involved in advertising use custom URL query parameters that enable them to track clicks on links. The most well-known example is probably the <code>?fbclid=<\/code> parameter that Facebook adds to outbound links.<\/p>\n<p>With the release of Firefox 102, Mozilla has added the new &#8220;Query Parameter Stripping&#8221; feature that automatically strips some of these query parameters. It does not matter whether you clicked\u00a0on a link or pasted the URL into the address bar.<\/p>\n<p>To enable Query Parameter Stripping, go into the Firefox Settings, click on <strong>Privacy &amp; Security<\/strong>, and then change <strong>Enhanced Tracking Protection<\/strong> to <strong>Strict<\/strong>.<\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" data-attachment-id=\"57938\" data-permalink=\"https:\/\/blog.malwarebytes.com\/exploits-and-vulnerabilities\/2022\/06\/update-now-mozilla-fixes-security-vulnerabilities-and-introduces-a-new-privacy-feature-for-firefox\/attachment\/strict\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/06\/Strict.png\" data-orig-size=\"936,883\" data-comments-opened=\"0\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"Strict\" data-image-description=\"\" data-image-caption=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/06\/Strict-300x283.png\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/06\/Strict-600x566.png\" width=\"600\" height=\"566\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/06\/Strict-600x566.png\" alt=\"Strict setting\" class=\"wp-image-57938\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/06\/Strict-600x566.png 600w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/06\/Strict-300x283.png 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/06\/Strict.png 936w\" sizes=\"auto, (max-width: 600px) 100vw, 600px\" \/><\/figure>\n<\/div>\n<p>You will need to click <strong>Reload All Tabs<\/strong> to apply the changes. If you find that setting <strong>Enhanced Tracking Protection<\/strong> to <strong>Strict<\/strong> could causes issues with certain sites, you can use the Manage Exceptions option to add these websites, or use the \u201cCustom\u201d setting to choose which trackers and scripts to block.<\/p>\n<h2>Updating<\/h2>\n<p>Under normal circumstances, updates will be applied without user intervention. You can check for the version number in the products\u2019 menu under&nbsp;<strong>Help<\/strong>&nbsp;&gt;&nbsp;<strong>About<\/strong><\/p>\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img decoding=\"async\" data-attachment-id=\"57939\" data-permalink=\"https:\/\/blog.malwarebytes.com\/exploits-and-vulnerabilities\/2022\/06\/update-now-mozilla-fixes-security-vulnerabilities-and-introduces-a-new-privacy-feature-for-firefox\/attachment\/firefox102\/\" data-orig-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/06\/Firefox102.png\" data-orig-size=\"673,369\" data-comments-opened=\"0\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"Firefox102\" data-image-description=\"\" data-image-caption=\"\" data-medium-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/06\/Firefox102-300x164.png\" data-large-file=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/06\/Firefox102-600x329.png\" loading=\"lazy\" width=\"600\" height=\"329\" src=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/06\/Firefox102-600x329.png\" alt=\"Firefox is up to date\" class=\"wp-image-57939\" srcset=\"https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/06\/Firefox102-600x329.png 600w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/06\/Firefox102-300x164.png 300w, https:\/\/blog.malwarebytes.com\/wp-content\/uploads\/2022\/06\/Firefox102.png 673w\" sizes=\"auto, (max-width: 600px) 100vw, 600px\" \/><\/figure>\n<\/div>\n<p>Should you not be using the latest version for some reason, e.g. automatic updates are disabled, then this screen will inform you that a new version is available and will start downloading it.<\/p>\n<p>When it\u2019s done, you&#8217;ll see a prompt to restart the browser. This will apply the update.<\/p>\n<p>Stay safe, everyone!<\/p>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/exploits-and-vulnerabilities\/2022\/06\/update-now-mozilla-fixes-security-vulnerabilities-and-introduces-a-new-privacy-feature-for-firefox\/\">Update now! Mozilla fixes security vulnerabilities and introduces a new privacy feature for Firefox<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n<p><a href=\"https:\/\/blog.malwarebytes.com\/exploits-and-vulnerabilities\/2022\/06\/update-now-mozilla-fixes-security-vulnerabilities-and-introduces-a-new-privacy-feature-for-firefox\/\" target=\"bwo\" >https:\/\/blog.malwarebytes.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><strong>Credit to Author: Pieter Arntz| Date: Thu, 30 Jun 2022 14:01:41 +0000<\/strong><\/p>\n<p>Mozilla has released Firefox updates to the Release Channel that fix several security vulnerabilities and introduce a new privacy feature called Query Parameter Stripping.<\/p>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\/exploits-and-vulnerabilities\/2022\/06\/update-now-mozilla-fixes-security-vulnerabilities-and-introduces-a-new-privacy-feature-for-firefox\/\">Update now! Mozilla fixes security vulnerabilities and introduces a new privacy feature for Firefox<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.malwarebytes.com\">Malwarebytes Labs<\/a>.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10488,10378],"tags":[26781,26782,26783,26784,26785,26786,26787,26788,22783,11122,26338,26789],"class_list":["post-19477","post","type-post","status-publish","format-standard","hentry","category-malwarebytes","category-security","tag-cve-2022-34468","tag-cve-2022-34470","tag-cve-2022-34478","tag-cve-2022-34479","tag-cve-2022-34482","tag-cve-2022-34483","tag-cve-2022-34484","tag-enhanced-tracking-protection","tag-exploits-and-vulnerabilities","tag-firefox","tag-ms-msdt","tag-query-parameter-stripping"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/19477","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=19477"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/19477\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=19477"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=19477"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=19477"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}