|
|
Subscribe / Log in / New account

Firefox 72.0.1 released

There is another Firefox release out there; this advisory suggests that updating quickly would be a good idea: "Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion. We are aware of targeted attacks in the wild abusing this flaw."


From:  Julien Cristau <jcristau-AT-mozilla.com>
To:  announce-AT-lists.mozilla.org
Subject:  Firefox 72.0.1 is now available
Date:  Thu, 9 Jan 2020 15:17:52 +0100
Message-ID:  <CALf+9VQPpf3G=HTaJHuzDCed-JPPtE_cGzsfL0fbVodPhJbUiw@mail.gmail.com>
Archive-link:  Article

Firefox 72.0.1 is now available as a free download for Windows, macOS, and
GNU/Linux from https://www.mozilla.org/firefox/new/.

We recommend that users keep up to date with the newest version of Firefox
for the latest features and fixes.

We are aware of targeted attacks in the wild abusing the flaw fixed in this
release; upgrading is strongly encouraged.

The full release notes are available at:
https://www.mozilla.org/firefox/72.0.1/releasenotes/

Julien Cristau
Firefox Release Manager
_______________________________________________
announce mailing list
announce@lists.mozilla.org
https://lists.mozilla.org/listinfo/announce


to post comments

about:config mitigation? Test?

Posted Jan 9, 2020 16:22 UTC (Thu) by mirabilos (subscriber, #84359) [Link] (3 responses)

Someone says that this can be mitigated by disabling something in about:config, but what?

How can I test whether $random_gecko_version_of_firefox_i_m_still_using_for_some_reason is vulnerable? (That is, is this IonMonkey a new Quantum thing, perchance?)

about:config mitigation? Test?

Posted Jan 9, 2020 19:40 UTC (Thu) by kenmoffat (subscriber, #4807) [Link] (1 responses)

No idea about what, if anything, you might be able to change in about:config, but https://security-tracker.debian.org/tracker/CVE-2019-17026 suggests the problem is not new (goes back to at least the earliest version there, 52.8.1esr)

about:config mitigation? Test?

Posted Jan 9, 2020 19:53 UTC (Thu) by mirabilos (subscriber, #84359) [Link]

The tracker does that by default, though.

about:config mitigation? Test?

Posted Jan 14, 2020 10:46 UTC (Tue) by nai9Ahz0 (guest, #112673) [Link]

Untested, but I'd expect setting javascript.options.ion to false should do the trick.


Copyright © 2020, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds