intermediate release of Firefox 67.0.2, in which has been resolved (CVE-2019-11702), specific to the Windows platform and allowing local files to be opened in Internet Explorer through manipulation of links that specify the "IE.HTTP:" protocol.
In addition to the vulnerability, this new release also fixes several unrelated issues:
- the console output of the JavaScript error "TypeError: data is null in PrivacyFilter.jsm", which could adversely affect the reliability and performance of session recovery;
- Resolved with a popup authentication dialog when connecting through a proxy;
- Resolved the issue of logging into the Pearson MyCloud service when using FIDO U2F;
- Adjusted the launch of the browser in safe mode, which caused crashes in Linux and macOS starting from Firefox 67 because the browser the profile as too new for the current version of Firefox;
- Verholpen to install and use additional language packs through the settings interface in Firefox versions provided by Linux distributions;
- In the developer tools, the fix introduced , which did not allow copying links and HTML tag code from the inspection window;
- Corrigeerd , which led to the inability to set a custom home page when clearing data before quitting in the settings options;
- problemen met de bouw van kernelmodules voor host-systemen met Linux bij gebruik van een niet-standaard of debug-configuratie (bijvoorbeeld bij het bouwen van modules vanuit een andere map); performance issues when running web applications based on the Eclipse RAP framework;
- crashes when launching on macOS 10.15;
- the launch of two parallel downloads through the "a" tag with the "download" attribute.
Bron: opennet.ru
