Mozilla sent Firefox Version 97.0 to the release channel today. The update includes eighteen security updates of which five (5) are rated high, six (6) are rated moderate, and one (1) are rated low.
Firefox ESR was updated to Version 91.6.
High
- #CVE-2022-22753:
Privilege Escalation to SYSTEM on Windows via Maintenance Service
- #CVE-2022-22754:
Extensions could have bypassed permission confirmation during update
- #CVE-2022-22762:
JavaScript Dialogs could have been displayed over other domains on Firefox for
Android
- #CVE-2022-22764:
Memory safety bugs fixed in Firefox 97 and Firefox ESR 91.6
- #CVE-2022-0511:
Memory safety bugs fixed in Firefox 97
Moderate
- #CVE-2022-22755:
XSL could have allowed JavaScript execution after a tab was closed
- #CVE-2022-22754:
Extensions could have bypassed permission confirmation during update
- #CVE-2022-22755:
XSL could have allowed JavaScript execution after a tab was closed
- #CVE-2022-22756:
Drag and dropping an image could have resulted in the dropped object being an
executable
- #CVE-2022-22757:
Remote Agent did not prevent local websites from connecting
- #CVE-2022-22758:
tel: links could have sent USSD codes to the dialer on Firefox for Android
- #CVE-2022-22759:
Sandboxed iframes could have executed script if the parent appended elements
- #CVE-2022-22760:
Cross-Origin responses could be distinguished between script and non-script
content-types
- #CVE-2022-22761:
frame-ancestors Content Security Policy directive was not enforced for framed
extension pages
Low
New
Firefox now supports and displays the new style of scrollbars
on Windows 11.
Fixed
On macOS, we’ve made improvements to system font loading which makes opening and switching to new tabs faster in certain situations.
Changed
- On February 8, we will be expiring the 18 colorway themes of Firefox version 94. This signals the end of a special, limited-time feature set. However, you can hold onto your favorite colorway, as long as you’re using it on the expiration date. In other words, if a colorway is “enabled” in the add-ons manager, that colorway is yours forever. Read more about colorway updates here.
·
Support for directly generating PostScript for printing on Linux
has been removed. Printing to PostScript printers still remains a supported
option, however.
Update: To get the update now, select "Help" from the Firefox
menu, then pick "About Firefox." Mac users need to select
"About Firefox" from the Firefox menu. If you do not use the English
language version, Fully Localized Versions are available
for download.
References
No comments:
Post a Comment