Tor Browser 7.0.3 is released
时间:2017-07-31 来源:torproject 作者:gk 条评论
Note: Tor Browser 7.0.3 is a security bugfix release for Linux users only. Users on Windows and macOS are not affected and stay on Tor Browser 7.0.2.
Tor Browser 7.0.3 is now available for our Linux users from the Tor Browser Project page and also from our distribution directory.
This release features an important security update to Tor Browser for Linux users. On Linux systems with GVfs/GIO support Firefox allows to bypass proxy settings as it ships a whitelist of supported protocols. Once an affected user navigates to a specially crafted URL the operating system may directly connect to the remote host, bypassing Tor Browser. Tails and Whonix users, and users of our sandboxed Tor Browser are unaffected, though.
The bug got reported to us yesterday by Julian Jackson (@atechdad) via our HackerOne bug bounty program. Thanks! We are not aware of it being exploited in the wild.
We are currently preparing updated Linux bundles for our alpha series and they should go live within the next couple of hours. Meanwhile Linux users on that series are strongly encouraged to use the stable bundles or one of the above mentioned tools that are not affected by the underlying problem.
Here is the full changelog since 7.0.2:
- Linux
- Bug 23044: Don't allow GIO supported protocols by default
来自https://blog.torproject.org/blog/tor-browser-703-released
注意:Tor Browser 7.0.3仅适用于Linux用户的安全修补程序版本。 Windows和MacOS上的用户不受影响,并停留在Tor Browser 7.0.2上。
Tor浏览器7.0.3现在可以从Tor浏览器项目页面和我们的发行目录中的Linux用户获得。
此版本为Linux用户的Tor浏览器提供了重要的安全更新。在支持GVfs / GIO的Linux系统上,Firefox允许绕过代理设置,因为它提供了受支持协议的白名单。一旦受影响的用户导航到特制的URL,操作系统可能会绕过Tor浏览器直接连接到远程主机。尾部和Whonix用户以及我们的沙盒Tor浏览器的用户不受影响。
这个bug昨天由Julian Jackson(@atechdad)通过我们的HackerOne漏洞奖励计划报告给了我们。谢谢!我们不知道在野外被剥削。
我们正在为我们的Alpha系列准备更新的Linux软件包,他们应该在接下来的几个小时内上线。同时,强烈建议使用该系列的Linux用户使用稳定的软件包或上述不受基础问题影响的工具之一。
这是7.0.2以来的完整更新日志:
Linux的
错误23044:默认情况下不允许支持GIO协议
来自https://blog.torproject.org/blog/tor-browser-703-released
