Tor Browser 6.0.5 is now available from the Tor Browser Project page and also from ourdistribution directory.s8Z免费翻墙网
This release features important security updates to Firefox including the recently disclosedextension update vulnerability. All users should upgrade as soon as possible.s8Z免费翻墙网
That vulnerability allows an attacker who is able to obtain a valid certificate for addons.mozilla.org to impersonate Mozilla's servers and to deliver a malicious extension update, e.g. for NoScript. This could lead to arbitrary code execution. Moreover, other built-in certificate pinnings are affected as well. Obtaining such a certificate is not an easy task, but it's within reach of powerful adversaries (e.g. nation states).s8Z免费翻墙网
Thanks to everyone who helped investigating this bug and getting a bugfix release out as fast as possible.s8Z免费翻墙网
We are currently building the alpha and hardened bundles (6.5a3 and 6.5a3-hardened) that will contain the fix for alpha/hardened channel users. We expect them to get released at the beginning of next week. Until then users are strongly encouraged to use Tor Browser 6.0.5.s8Z免费翻墙网
Apart from fixing Firefox vulnerabilities this release comes with a new Tor stable version (0.2.8.7), an updated HTTPS-Everywhere (5.2.4), and fixes minor bugs.s8Z免费翻墙网
Here is the full changelog since Tor Browser 6.0.4:s8Z免费翻墙网
- All Platforms
- Update Firefox to 45.4.0esr
- Update Tor to 0.2.8.7
- Update Torbutton to 1.9.5.7
- Bug 19995: Clear site security settings during New Identity
- Bug 19906: "Maximizing Tor Browser" Notification can exist multiple times
- Update HTTPS-Everywhere to 5.2.4
- Bug 20092: Rotate ports for default obfs4 bridges
- Bug 20040: Add update support for unpacked HTTPS Everywhere
- Windows
- Bug 19725: Remove old updater files left on disk after upgrade to 6.x
- Linux
- Bug 19725: Remove old updater files left on disk after upgrade to 6.x
- Android
- Bug 19706: Store browser data in the app home directory
- Build system
s8Z免费翻墙网
来自https://blog.torproject.org/blog/tor-browser-605-releaseds8Z免费翻墙网
|