On CBS MoneyWatch: Who Does the Most College Drinking?
BNET Business Network:
BNET
TechRepublic
ZDNet

January 30th, 2008

Mozilla ups unpatched Firefox flaw to 'high severity'; Preps fix

Posted by Larry Dignan @ 4:50 am

Categories: Browsers, Data theft, Exploit code, Firefox, Hackers, Mozilla, Open source, Patch Watch, Vulnerability research

Tags: Mozilla Firefox, Vulnerability, Severity, Mozilla Corp., Add-on, Flaw, Window Snyder, Web Browsers, Security, Internet

Mozilla has given a proof of concept Firefox vulnerability a “high severity” rating because an attacker can collect session information such as cookies and history, according to Mozilla security chief Window Snyder.

Snyder said the vulnerability will be patched with Firefox 2.0.0.12, which will be pushed out “shortly.”

On Jan. 22, Snyder confirmed a proof of concept vulnerability discovered by researcher Gerry Eisenhaur on Jan. 19. Simply put, Firefox leaks information that can allow an attacker to load any javascript file on a machine. This “chrome protocol directory transveral” is in play whenever there are “flat” files–common in add ons–are installed. Chances are good that most Firefox users will have at least a few of these add ons installed. That’s a lot of data leakage.

Mozilla initially gave the flaw a low severity rating, but changed its mind after further investigation.

Snyder writes:

An attacker can use this vulnerability to collect session information, including session cookies and session history.  Firefox is not vulnerable by default. If you are an author of any of these add-ons, please release an update to your add-on that uses .jar packaging.

The list of the add-ons affected is long, but Snyder noted it was only a partial list. A few add-ons that stuck out.

  • ajax_yahoo_mail_viamatic_webmail_-0.9-fx+fl
  • quickjava-0.4.2-fx
  • open_java_console-1.5-fx
  • firefoxit-0.1.2-fx+fl
  • ie_view_lite-1.2-fx
  • extended_statusbar-1.2.4-fx
  • sourceforge_direct_download-0.4-fx
  • no_new_window-0.1-fx
  • farky-1.1.3-fx
  • livejournal_friends_checker-0.8.1.1-fx
  • termblaster_firefox_edition_-1.3.7-fx
  • myurlbar_a-2006.04.19-fx
  • pingpong-0.7-fx
  • print_print_preview-0.3-fx
  • world_of_warcraft_realm_status_tool-0.2-fx
  • settlers_3d_connector_user_info-0.1-fx
  • gmail_skins-0.9.8-fx
  • firephish_anti-phishing_extension-0.1.1-fx
  • bookmark_sync_and_sort-1.0.6-fx
  • inline_blocked_image_view-1.1-fx
  • myspace_friend_renamer-.75-fx
  • facebook_o-state_cowboy_style-1.2-fx
  • flickrgethighrez-2007.02.06-fx
  • refspoof-0.9.1-fx
  • arfcom_ad_blocker-1.0-fx
  • downloads_in_tab-0.0.2-fx
  • adwords_keyword_multiplier-0.1-fx
  • livejournal_addons-5.2.7-fx

Other links of note about this problem:

Larry DignanLarry Dignan is Editor in Chief of ZDNet and Editorial Director of ZDNet sister site TechRepublic. See his full profile and disclosure of his industry affiliations.

  • Talkback
  • Most Recent of 98 Talkback(s)
save your money
I'm not very good at humor. When I knew less about computers I searched for a way to get rid of IE, Win. Media Player, etc., etc., etc., After exhausting my research it became very obvious that it was impossible. I had no expectation of spending $1.
Dawn... (Read the rest)
Posted by: dariced@... Posted on: 02/01/08 You are currently: a Guest | | Terms of Use
Since one cannot remove IE, ....  ShadeTree | 01/30/08
Message has been deleted.  Intellihence | 01/30/08
For a last note , Mirosoft is put on notice again .  Intellihence | 01/30/08
It seems you are the only one showing bias.  ShadeTree | 01/30/08
Good catch  Badgered | 01/30/08
Please don't....  cornpie | 01/30/08
amen to that  Larry DignanZDNet Moderator | 01/30/08
Greate Post.  No_Ax_to_Grind | 01/30/08
Yes, abide by it No_Axe  deaf_e_kate | 01/30/08
The Troll Couldn't Hear You  itanalyst | 01/30/08
Isn't that the norm  voska1 | 01/30/08
Malware is Terrorism  wellduh | 01/30/08
Sorry I can't help seeing both sides  wellduh | 01/30/08
Hear Hear  RiggsFolly | 01/31/08
If you read the story you would have found out  Intellihence | 01/30/08
I get it.  xuniL_z | 01/30/08
Haven't you read the others posting to you on topic  Boot_Agnostic | 01/30/08
That's just proves...  jnoooo | 01/30/08
What about the Leopard/Tiger flaw they're ignoring?  rpmyers1 | 01/30/08
WOW. And Apple calls the fix an enhancement.. not surprised.  xuniL_z | 01/30/08
But no one will exploit it  wellduh | 01/30/08
Cannot remove IE?  NMITGuy | 01/30/08
Please post SAFE instructions  wackoae | 01/30/08
I highly doubt it.  ShadeTree | 01/30/08
IE absolutely cannot be removed.  joe.smetona@... | 01/30/08
When to say "Uncle"  joe.smetona@... | 01/30/08
Can't Remove IE? How? I'll send you $$$  dariced@... | 01/30/08
Save your money.  joe.smetona@... | 01/31/08
save your money  dariced@... | 02/01/08
Re: Since one cannot remove IE, ....  none none | 01/30/08
I believe I made my point.  ShadeTree | 01/30/08
Re: I believe I made my point.  none none | 01/30/08
Re: Re: I believe I made my point.  none none | 01/30/08
Search Answer  DarienHawk67 | 01/30/08
Re: Search Answer  none none | 01/30/08
Using IE is less secure than not using it.  CobraA1 | 01/30/08
Read the title of this article.  ShadeTree | 01/30/08
At least you have the option to uninstall FireFox  voska1 | 01/30/08
Not more secure at all.  ShadeTree | 01/30/08
And hence you are more secure  voska1 | 01/30/08
Message has been deleted.  Raymond Danner | 01/31/08
Message has been deleted.  thungurknifur | 02/01/08
Not True  wellduh | 01/30/08
But yes...  wellduh | 01/30/08
Absolutely true!  ShadeTree | 01/31/08
It's under the bridge!  thungurknifur | 01/31/08
You just did!(nt)  ShadeTree | 02/01/08
Window's report of software affected by FF flaw, too long to list  xuniL_z | 01/30/08
Mozilla reported the flaw  jorjitop | 01/30/08
I did say  xuniL_z | 01/30/08
FUD  albill | 01/30/08
I'm guilty of nothing more than being a realist.  xuniL_z | 01/30/08
Re: I'm guilty of nothing more than being a realist.  none none | 01/30/08
FUD II  albill | 01/30/08
Re: FUD II  Greenknight_z | 01/30/08
A suggestion for you albill.......  xuniL_z | 01/31/08
GK...i actually meant to say  xuniL_z | 01/31/08
RE: Mozilla ups unpatched Firefox flaw to 'high severity'; Preps fix  claires999 | 01/30/08
'both'?  Borg_Tribble | 01/30/08
My guess  DannyO_0x98 | 01/30/08
Firefox: the browser we DO NOT trust!  qmlscycrajg | 01/30/08
Browser Who Doesn't Trust?  radar696@... | 01/30/08
One More Thing!  radar696@... | 01/30/08
Well, you can always not use IE if you so choose (nt)  tikigawd | 01/30/08
Both browsers have flaws  tikigawd | 01/30/08
When used with Windows, due to Windows file handling.  joe.smetona@... | 01/30/08
Great deflection...  transposeIT | 01/30/08
Unfortunately...  joe.smetona@... | 01/31/08
Firefox: the browser we DO NOT trust!  morph000 | 01/30/08
Ok...  ego.sum.stig@... | 01/30/08
There is no answer to that question.  xuniL_z | 01/31/08
At least they fix severe flaws a LOT quicker than MS does  hkommedal | 01/30/08
To which I respond,  Raymond Danner | 01/31/08
And yet Firefox remains flawed and rates ...  ShadeTree | 01/31/08
RE: Mozilla ups unpatched Firefox flaw to 'high severity'; Preps fix  LuciusF@... | 01/30/08
Overstated use of add-ons....  techboy_z | 01/30/08
I have 14 addons installed.  KWierso | 01/30/08
What I would like to see.  joe.smetona@... | 01/30/08
who cares about linux? only 2% of install base  qmlscycrajg | 01/30/08
Ah but people might start caring  voska1 | 01/30/08
You are saying that because much fewer people use linux  hkommedal | 01/30/08
So go to a Linux-centric blog  tikigawd | 01/30/08
Since one can use Opera, I guess that's where the many will flock  Boot_Agnostic | 01/30/08
Of the 601 addons/extensions in that (partial?) list  LazLong | 01/30/08
Practice a little safe hex.  hulse_kevin | 01/30/08
still the same  LightSpeed | 01/30/08
plugins vs addons  hulse_kevin | 01/30/08
Ever heard of Netscape?  hulse_kevin | 01/30/08
This is the same argument ...  david@... | 01/30/08
Amen  supra5mge | 01/30/08
Ditto  DarienHawk67 | 01/30/08
NoScript...?  LazLong | 01/30/08
No Script  dariced@... | 01/30/08
Firefox flaw unimportant  wellduh | 01/30/08
Firefox Flaw Unimportant.  dariced@... | 01/30/08
A few more thoughts.  joe.smetona@... | 01/31/08
Who cares  HapGail_HomeInMd@... | 01/31/08
Why  pablo Dante | 02/01/08

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

advertisement

Recent Entries

advertisement

Archives

Favorite Links

ZDNet Blogs

White Papers, Webcasts, and Downloads