Monday November 24, 2008 4:14 AM AEST
Latest Comments
"it's good one "
by khanbhai | Nov 22, 2008 9:00 PM
 
"when i login to face book it tells me i am cookies enabled what does this mean"
by celeste | Nov 21, 2008 5:15 PM
 
"Hi this is the mail I received Brett Karpman show details Nov 17 (3 days ago) Reply Atten..."
by Rodney Churchyard | Nov 20, 2008 6:13 PM
 
"security through obscurity...shows how detached HIPAA is from reality."
by priceOfFishInChina | Nov 20, 2008 1:19 PM
 
"Umm. no. The 6.5 product is mounting the offline VM image and performing a scan for patch ..."
by eric | Nov 20, 2008 8:15 AM
Web

New Firefox flaw deemed low-risk threat

  • Email a Friend
  • Print Page
New Firefox flaw deemed low-risk threat
By Dan Kaplan
Jan 25, 2008 9:47 AM
Tags: "firefox | vulnerability" | "firefox | security" | firefox | mozilla | security" | web | browser | security" |
Mozilla officials are investigating a new vulnerability in Firefox that could be exploited by attackers to steal files from a victim's machine.

Window Snyder, security chief for Firefox, said on her blog Tuesday that the flaw is located in the chrome protocol handler, which controls the various widgets on a browser.

The vulnerability, discovered by researcher Gerry Eisenhaur, could allow attackers to load malicious JavaScript onto a victim's PC by luring them to a hacked website, she said.

“Attackers may use this method to detect the presence of files, which may give an attacker information about which applications are installed,” Snyder wrote. “This information may be used to profile the system for a different kind of attack.”

She said individuals are only susceptible if they have downloaded “flat” add-ons, including Download Statusbar, which lets users track ongoing and completed downloads in the status bar, or Greasemonkey, which permits users to install scripts to make changes to webpages.

“Flat” add-ons do not store their contents in a JAR archive; therefore their contents could permit attackers to read random files on the hard drive, according to Mozilla.

But Jeremiah Grossman, chief technology officer of WhiteHat Security, told SCMagazineUS.com that he considers the bug – which garnered a “less critical” rating from Secunia – to not be a serious problem, as few users are impacted.

However, a number of more severe vulnerabilities affecting URI protocol handlers have recently popped up, affecting Firefox and Internet Explorer browsers, Grossman said.

“There have been lots of problems in that particular space that were really bad and did affect a lot of people,” he said. “Web browsers are complex things. Anytime you have more functionality, the greater opportunity you have for bugs to occur.”

See original article on scmagazineus.com

Secure Computing Magazine

 
Ads by Google
Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 
Tripwire - Click here to win an iTouch
 
 
 
Vulnerabilities & Exploits Whitepapers