Tor Browser 7.5a3 is released
时间:2017-07-30 来源:torproject 作者:gk 条评论
Tor Browser 7.5a3 is now available for our Linux users from the Tor Browser Project page and also from our distribution directory.
This release features an important security update to Tor Browser for Linux users. On Linux systems with GVfs/GIO support Firefox allows to bypass proxy settings as it has a whitelist of supported protocols. Once an affected user navigates to a specially crafted URL the operating system may directly connect to the remote host, bypassing Tor Browser. Tails and Whonix users, and users of our sandboxed Tor Browser are unaffected, though.
The bug got reported to us by Julian Jackson (@atechdad) via our HackerOne bug bounty program on July 26. Thanks! We are not aware of it being exploited in the wild.
Here is the full changelog since 7.5a2:
- Linux
- Bug 23044: Don't allow GIO supported protocols by default
来自https://blog.torproject.org/blog/tor-browser-75a3-released
注意:Tor Browser 7.5a3是仅针对Linux用户的安全错误修复版本。 Windows和MacOS上的用户不受影响,并停留在Tor Browser 7.5a2上。
Tor浏览器7.5a3现在可以从Tor浏览器项目页面和我们的发行目录中的Linux用户获得。
此版本为Linux用户的Tor浏览器提供了重要的安全更新。在支持GVfs / GIO的Linux系统上,Firefox允许绕过代理设置,因为它具有受支持协议的白名单。一旦受影响的用户导航到特制的URL,操作系统可能会绕过Tor浏览器直接连接到远程主机。尾部和Whonix用户以及我们的沙盒Tor浏览器的用户不受影响。
Julius Jackson(@atechdad)通过我们的7月26日的HackerOne错误奖赏计划向我们报告了这个错误。谢谢!我们不知道在野外被剥削。
这是7.5a2以来的完整更新日志:
Linux的
错误23044:默认情况下不允许支持GIO协议
来自https://blog.torproject.org/blog/tor-browser-75a3-released
