BetaONE will rise again!


Reply
  #1  
Old 30th Jan 08, 04:45 PM
NewsBot's Avatar
NewsBot NewsBot is offline
Senior Member
 
Join Date: Oct 2004
Posts: 31,027
NewsBot will become famous soon enough
Mozilla ups unpatched Firefox flaw to high severity'
Mozilla has given a proof of concept Firefox vulnerability a “high severity” rating because an attacker can collect session information such as cookies and history, according to Mozilla security chief Window Snyder. Snyder said the vulnerability will be patched with Firefox 2.0.0.12, which will be pushed out “shortly.” On Jan. 22, Snyder confirmed a proof of concept vulnerability discovered by researcher Gerry Eisenhaur on Jan. 19. Simply put, Firefox leaks information that can allow an attacker to load any javascript file on a machine. This “chrome protocol directory transveral” is in play whenever there are “flat” files–common in add ons–are installed. Chances are good that most Firefox users will have at least a few of these add ons installed. That’s a lot of data leakage.

View: Full Story @ ZDNet

Read full story...



More...
Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is On
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Mozilla Firefox for Windows 2.0.0.10 NewsBot DriverHeaven News 0 26th Nov 07 11:31 PM
Mozilla Firefox for Windows (Gran Paradiso) 3.0 Alpha 8 NewsBot DriverHeaven News 0 21st Sep 07 12:32 AM
Mozilla Firefox 2.0.0.4 NewsBot NeoWin News 0 30th May 07 04:37 PM
Unpatched Firefox flaw may expose users NewsBot NeoWin News 0 10th Sep 05 12:30 PM
Neowin Member Interview: Asa Dotzler - Firefox Developer NewsBot NeoWin News 0 20th Jul 05 10:30 PM


All times are GMT +1. The time now is 11:54 PM.


Design by Vjacheslav Trushkin for phpBBStyles.com.
Powered by vBulletin® Version 3.6.5
Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.