Tuesday December 2, 2008 4:12 AM AEST
Latest Comments
"Concerned man's comments seem to intimate that if I'm using agents all will be well but the ..."
by Werner K | Nov 26, 2008 8:36 PM
 
"That will enhance Microsoft Office system, including SharePoint - good platform for enterprise ..."
by SGE | Nov 25, 2008 3:29 PM
 
"how many users allow per session? because the digital persona password manager allows only 10 ..."
by Daniel | Nov 25, 2008 12:14 AM
 
"security through obscurity...shows how detached HIPAA is from reality."
by priceOfFishInChina | Nov 20, 2008 1:19 PM
 
"I have been the recipient of Agent.JEN.Trojan through an email suggesting a UPS parcel (including..."
by Vincent Laing | Nov 13, 2008 4:01 PM

Student details flaw in Firefox add-ons

  • Email a Friend
  • Print Page
Student details flaw in Firefox add-ons
By Dan Kaplan
May 30, 2007 5:35 PM
Tags: With | patch | release | looming, | student | details | flaw | in | Firefox | add-ons
Christopher Soghoian said on his blog today that a flaw exists in the "upgrade mechanism" used in Firefox extensions, or add-ons that lend additional functionality to the browser - namely third-party toolbars.

"The vulnerability is made possible through the use of a man-in-the-middle attack, a fairly old computer security technique," Soghoian wrote today.

"Essentially, an attacker must somehow convince your machine that he is really the update server for one or more of your extensions, and then the Firefox browser will download and install the malicious update without alerting the user to the fact that anything is wrong."

In lieu of a fix, Soghoian suggests users remove or disable Firefox extensions except those downloaded from the official Mozilla add-ons site.

Mike Shaver, Mozilla's director of ecosystem development, told SCMagazine.com in a statement that the users of Mozilla-hosted add-ons are not at risk. He instead pinned the blame on the third-party providers.

"Users of add-ons that are insecurely hosted/updated are vulnerable to remote code execution if their network is compromised," he said. "We strongly encourage the providers of such add-ons to remedy their hosting situation promptly to minimize the exposure to the users of their software."

Soghoian added that many of the third-parties who provide the extensions, such as Yahoo, Google and Facebook, were notified of the bug but have yet to release a patch.

Meanwhile, Mozilla is expected to push out the latest updates for Firefox today.

The fixes also mark the last release for version 1.5, for which support ends today, according to the Mozilla Developer Center site. Firefox 1.5.0.12 contains a component that can automatically upgrade users to version 2.0 of the alternative browser.

The company suggested that all users download the latest version to "benefit from features that make search, communication and online security more effective."

The updates will be detailed here.

 
Ads by Google
Thoughts on this article? Add a comment below.
Be the first to comment on this article.

Report this comment as offensive:

   * Indicates information we require to process your submission.

Name: *
Email: *
Reason for offense: *
Your report will not be displayed.  
Name:
*
 
Email:
(will not be displayed)
*
 
Comment:
(HTML not permitted)
*
 
Validation
*

Enter the code you see below:

 

 
 
 
 
 
Tripwire - Click here to win an iTouch
 
 
Patch Management Whitepapers