« Navy "rail gun" closer to reality | Main | Additional updates completed on Early Warning Systems »

Firefox users listen up

Just when you thought it was safe to troll in the WWW waters with Firefox, comes this article on TechRepublic about a new flaw that has the potential to cause problems reminiscent of IE.

Window Snyder, Mozilla’s chief of security confirmed a data leak vulnerability in Firefox’s directory traversal mechanism. The flaw has been graded as a low-risker and was brought to light as a proof of concept.

Wait, what?? (and Mozilla's main security guru has a first name of "Window"??????)

When a “flat” add-on is present, an extension which stores its information within Javascript files as opposed to .jar files, an attacker exploiting this flaw may be able to retrieve data or profile a compromised system. Extensions such as Greasemonkey and Download Statusbar may be affected.

Sounds rather IE-ish to me. At least they say it's a low risk flaw.....

Check the TechRepublic article for links to the full report.

Return radar screens to normal scanning mode.

TrackBack

TrackBack URL for this entry:
http://www.area5xp.net/cgi-bin/mt-tb.cgi/28

Post a comment

(If you haven't left a comment here before, you may need to be approved by the site owner before your comment will appear. Until then, it won't appear on the entry. Thanks for waiting.)

About

This page contains a single entry from the blog posted on January 24, 2008 4:18 PM.

The previous post in this blog was Navy "rail gun" closer to reality.

The next post in this blog is Additional updates completed on Early Warning Systems.

Many more can be found on the main index page or by looking through the archives.

Creative Commons License
This weblog is licensed under a Creative Commons License.