Stories
Slash Boxes
Comments

SoylentNews is people

Submission Preview

Link to Story

Tor Browser 13.0.13 unscheduled emergency release

Accepted submission by Anonymous Coward at 2024-03-24 01:40:43
Security

https://blog.torproject.org/new-release-tor-browser-13013/ [torproject.org]

"This is an unscheduled emergency release with important security updates to Firefox for Desktop platforms. Android is unaffected."

https://www.mozilla.org/en-US/security/advisories/mfsa2024-16/#CVE-2024-29944 [mozilla.org]

Mozilla Foundation Security Advisory 2024-16
Security Vulnerabilities fixed in Firefox ESR 115.9.1

Announced
March 22, 2024

https://www.mozilla.org/en-US/security/advisories/mfsa2024-16/#CVE-2024-29944 [mozilla.org]

CVE-2024-29944: Privileged JavaScript Execution via Event Handlers

Reporter
Manfred Paul via Trend Micro's Zero Day Initiative

Impact critical

Description

An attacker was able to inject an event handler into a privileged object that would allow arbitrary JavaScript execution in the parent process. Note: This vulnerability affects Desktop Firefox only, it does not affect mobile versions of Firefox.

Tails 6.0 is affected. Please update Tails 6.0 to the current version when they release it.


Original Submission