On CBS MoneyWatch: 5 Things You Should Buy at Walmart
BNET Business Network:
BNET
TechRepublic
ZDNet

January 23rd, 2008

Mozilla confirms Firefox proof of concept information leak vulnerability

Posted by Larry Dignan @ 2:12 am

Categories: Browsers, Data theft, Firefox, Patch Watch, Responsible disclosure, Vulnerability research

Tags: Mozilla Firefox, Attacker, Vulnerability, Mozilla Corp., Window Snyder, Web Browsers, Security, Internet, Larry Dignan

Mozilla’s security chief Window Snyder has confirmed a proof of concept information leak flaw in Firefox–even fully patched versions.

Snyder confirmed the issue in a blog post. The proof of concept vulnerability was highlighted by researcher Gerry Eisenhaur on Jan. 19. In a nutshell, Firefox leaks information that can allow an attacker to load any javascript file on a machine.

Technically, it’s a chrome protocol directory transversal. Snyder explains:

When a chrome package is “flat” rather than contained in a .jar the directory traversal allows escaping the extensions directory and reading files in a predictable location on the disk. Many add-ons are packaged in this way.

A visited attacking page is able to load images, scripts, or stylesheets from known locations on the disk. Attackers may use this method to detect the presence of files which may give an attacker information about which applications are installed. This information may be used to profile the system for a different kind of attack.

Some extensions may store information in Javascript files and an attacker may be able to retrieve those. Greasemonkey user scripts may be retrieved using this method. Session storage and preferences are not readable through this technique.

Mozilla gives the flaw an low severity rating for now, but add ons such as Download Statusbar and Greasemonkey are vulnerable. Look for this vulnerability to get patched low risk or not. Mozilla has opened a bug.

Larry DignanLarry Dignan is Editor in Chief of ZDNet and Editorial Director of ZDNet sister site TechRepublic. See his full profile and disclosure of his industry affiliations.

  • Talkback
  • Most Recent of 42 Talkback(s)
RE: Mozilla confirms Firefox proof of concept information leak vulnerability
Nice..
thanks

Reverse Phone Lookup || Cell Phone Lookups || Read the rest)
Posted by: blurayripper Posted on: 09/22/09 You are currently: a Guest | | Terms of Use
The more I use firefox, the less impressed...  bjbrock | 01/23/08
IE  oregonnerd13 | 01/23/08
6 one half dozen the other  voska1 | 01/23/08
not true, because this flaw is known since August  qmlscycrajg | 01/23/08
versus...  Amaroq | 01/23/08
Reports to Google??  techboy_z | 01/23/08
Reports to Goolgle  jacarter3 | 01/23/08
I just blocked outgoing traffic to  bjbrock | 01/23/08
Ya Know...  LazLong | 01/23/08
*sigh*  Amaroq | 01/23/08
Plain-vanilla Firefox not vulnerable  Greenknight_z | 01/25/08
RE: Mozilla confirms Firefox proof of concept information leak vulnerabilit  brotherjim01@... | 01/23/08
To each his own I guess  Cayble | 01/23/08
Mozilla is sleeping! This patch is known since August!  qmlscycrajg | 01/23/08
Not the same bug  Greenknight_z | 01/25/08
Mozilla is sleeping! This flaw is known since August!  qmlscycrajg | 01/23/08
Qmiscycraig@...,  mhenriday | 01/23/08
Not excatly.  phatkat | 01/23/08
NoScript  paul.byford | 01/23/08
Yes it prevents this problem  Giorgio Maone | 01/23/08
noscript does NOT protect!  qmlscycrajg | 01/24/08
Follow Giorgio's link -  Greenknight_z | 01/25/08
RE: Mozilla confirms Firefox proof of concept information leak vulnerabilit  The Rationalist | 01/23/08
Agreed  judgesinel@... | 01/23/08
Ya good, Bye  judgesinel@... | 01/23/08
Fox under Linux + NoScript + FlashBlock = bolted down security  Don Collins | 01/23/08
Just for the record,  mhenriday | 01/23/08
How many of these chrome-related security holes have we seen now? (NT)  PB_z | 01/23/08
yawn...  JDThompson | 01/23/08
He must not like to fix his own problems.  Amaroq | 01/23/08
Still Rather Use This Than IE  itanalyst | 01/23/08
OPERA!!!  Horus418 | 01/23/08
If you don't advertise your wares  Boot_Agnostic | 01/23/08
Just wipe the cache and restart Fox before online banking  Don Collins | 01/24/08
What?  Horus418 | 01/24/08
RE: Mozilla confirms Firefox proof of concept information leak vulnerabilit  martin.pisto@... | 01/24/08
Link  martin.pisto@... | 01/24/08
More information is needed in the articles.  joe.smetona@... | 01/24/08
Mozilla Firefox is just as vulnerable as any other web browser  John Musbach | 01/24/08
No, it's not, because it's patched quickly.  Greenknight_z | 01/25/08
Probably when just used on Windows.  joe.smetona@... | 01/25/08
RE: Mozilla confirms Firefox proof of concept information leak vulnerability  blurayripper | 09/22/09

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement
Click Here

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads

SmartPlanet

Click Here