Home | Extensions, Firefox, News, Security | Firefox vulnerability affects some extensions
-->

Firefox vulnerability affects some extensions

Published: January 23rd, 2008
  •  Print

A vulnerability in how Firefox handles chrome: addresses, which are used to load specific Firefox and extensions’ interface elements like windows, buttons and dialogs, could allow a malicious site to access local files in known locations.

The vulnerability affects extensions that are installed as a set of uncompressed files, as opposed to the more common .jar files. Download Statusbar and Greasemonkey are some of the most popular extensions affected.

Devon Jensen, developer of Download Statusbar has promptly released an update (0.9.5.3) that repackages the extension as a .jar file. If you are using this extension you can update by loading the Addons Manager (in the Tools menu, select Add-ons) and clicking on Find Updates.

There are many extensions that are deployed this way so it’s very hard to tell if you are affected or not. In the meantime you may want to disable temporarily your less frequently used extensions.

Mozilla Security has acknowledged the vulnerability (with an initial serverity of low) and is working on a solution as you read this.

You can leave a response, or trackback from your own site.

1 Comments on “Firefox vulnerability affects some extensions”

Subscribe to this post's RSS feed

  1. 1. Richard Baldonado
    February 12th, 2008 at 2:20 pm

    Hello,

    The following link to a directory, does not work in FireFox and it works in Internet Explorer.

    * [Integrated Install Logs(IE only)|file://66.77.67.219/scm_logs/Integrated]

    Any help would be appreciated.

    –Richard Baldonado

    [Reply]

3 Trackbacks/Pings (Trackback URL)

  1. 1. Vulnerabilidade do Firefox afecta algumas extensões | Open Mania January 23rd, 2008 at 3:19 pm
  2. 2. The Week in Hidden Firefox Links | Firefox Facts January 25th, 2008 at 8:23 am
  3. 3. Firefox vulnerability severity raised, fix on its way : Mozilla Links January 29th, 2008 at 11:10 pm

Leave a Reply




Comment:

Firefox 3

Links

  • Online Shopping
  • Document Scanning Services
  • 5GB free for your music
  • Voucher Codes & Discount Codes
  • CyberDefender Software
  • Recent Entries

    Recent Comments