If you use the eloquence64 #eloquence addon for the #NVDA #screenreader, a critical security release is now available. This is a critical update! Please update as soon as possible.
If you use Eloquence64 on secure screens, after the update, you must IMMEDIATELY! go to NVDA's settings dialogue, select eloquence from the list box, and press the "copy helper to system config" button again.
It fixes the following issues:
* fix: eloquence64 now clears its log file on start
* Fix: in some cases, eloquence64 could write to its log file at 30 megs per second
* fix: in some cases, eloquence64 created multiple temp files and directories that could not be removed
* fix: in some cases, eloquence64 could unexpectedly leave a port open on the computer
* fix: the port and key to communicate with eloquence could be intercepted by other processes running on the machine
* fix: in rare cases, it could have been possible for other processes on the user's machine to cause the addon to load and run arbitrary Python code by causing it to deserialize an attacker supplied pickle. If the addon was running on a secure screen, this would mean instant privilege escalation.
* fixed: crashing or frozen NVDA will no longer leave orphaned eloquence processes behind
* fix: more reliable pause and break lengths
* security hardening: switch to named pipes with DACL for IPC, ensuring no other process can use the 32-bit host
Release page: github.com/fastfinge/eloquence_64/releases/tag/v21
Direct download: github.com/fastfinge/eloquence_64/releases/download/v21/Eloquence-v21.nvda-addon
#nvdasr