This text is designed and written as a supplement to 'What I Learned in 10 Years on Stack.

Emergency security releases for Firefox have been published 72.0.1 and 68.4.1, which address critical vulnerability (CVE-2019-17026), which allows for code execution when opening specially crafted pages. The danger is compounded by the fact that even before the fix was made were recorded there have been confirmed instances of attacks exploiting this vulnerability, and a working exploit is in the hands of malicious actors. All Firefox users are strongly advised to update their browser urgently, while Tor Browser users need to wait for the release of version 9.0.4, which will be published within a few hours.

Signs of attacks exploiting the 0-day vulnerability were discovered by Chinese antivirus software producers Qihoo 360. The issue is caused by incorrect type definition of array elements during operations StoreElementHole and FallibleStoreElement in object code compiled by the JIT engine IonMonkey. Details are still not disclosed, but the patch code is available for analysis..

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster