intermediate release of Firefox 67.0.2, which addresses (CVE-2019-11702), a Windows-specific vulnerability that allows opening a local file in Internet Explorer through manipulation of links that specify the protocol "IE.HTTP:".
In addition to the vulnerability, the new release also fixes several non-security related issues:
- the JavaScript console error "TypeError: data is null in PrivacyFilter.jsm," which could negatively affect the reliability and performance of session restoration;
- Addressed with the display of a proxy connection authentication dialog;
- Resolved an issue with logging into the Pearson MyCloud service when using FIDO U2F;
- Improved the browser's safe mode launch, which on Linux and macOS since Firefox 67 crashed because the browser the profile too new for the current version of Firefox;
- Resolved installation and usage of additional language packs through the settings interface in Firefox versions provided by Linux distributions;
- In the developer tools, fixed , which prevented copying links and HTML tag code from the inspection window;
- Fixed , leading to the inability to set a custom homepage when configuring the option to clear data on exit;
- Resolved performance issues when running web applications based on the Eclipse RAP framework;
- crash when launching in macOS 10.15;
- launching two parallel downloads via the "a" tag with the "download" attribute.
Source: opennet.ru
