Urgent update for Tor Browser users due to a critical vulnerability. Users on macOS and Linux are affected, but not on Windows and Tails.
The Tor project releases a 7.0.9 update for the Tor Browser. Users on macOS and Linux must apply it urgently, while those on Windows are not affected. Blamed for a security vulnerability with code name TorMoil.
The flaw is related to a bug affecting Firefox. Remember that to browse the Tor anonymization network, the Tor Browser software relies on Firefox ESR. The bug is at the processing of links file: // (in an address).
The concern is of no serious consequence for Firefox, but it is a completely different matter in Tor Browser with the possibility of a leak of the real IP address of the user. "When an affected user accesses a specially crafted URL, the operating system can connect directly to the remote host, bypassing the Tor Browser."
Related:He is sentenced to prison for selling VPN in China
Tor Project points out that users of the Tails distribution and with Tor Browser in sandboxed version are not affected. The problem was reported by Filippo Cavallarin of We Are Segment on October 26th.
The next day, a mitigation measure was developed with Mozilla engineers, but it is October 31st that a complete patch has been developed. There is no report about exploiting vulnerability in attacks.
Last year, the Tor project ushered in a bug bounty program. Only by invitation, it was made public this summer, still via the platform HackerOne.
💌 Follow by Email:Digital Channel
🌍🔍 Search Google :digitalchannel.tk
Click Index You Might Be Interested
suivre Dhaouadi Aymensur