Tor Browser before 7.0.9 on macOS and Linux allows remote attackers to bypass the intended anonymity feature and discover a client IP address via vectors involving a crafted web site that leverages file:// mishandling in Firefox, aka TorMoil. NOTE: Tails is unaffected.
https://www.debian.org/security/2018/dsa-4327
https://trac.torproject.org/projects/tor/ticket/24052
https://security.gentoo.org/glsa/201811-13
https://security.gentoo.org/glsa/201810-01
https://lists.debian.org/debian-lts-announce/2018/11/msg00011.html
https://blog.torproject.org/tor-browser-709-released
https://access.redhat.com/errata/RHSA-2018:3458
https://access.redhat.com/errata/RHSA-2018:3403