View Full Version : Two 'extremely critical' vulnerabilities in Firefox
hankster
Sun 8th May '05, 4:58pm
http://secunia.com/advisories/15292/
MrNase
Sun 8th May '05, 5:28pm
Thanks for that notification :)
evssadmin
Sun 8th May '05, 6:05pm
http://secunia.com/advisories/15292/
Apperciate the notification. thanks.
Moparx
Sun 8th May '05, 9:33pm
nothing to worry about unless you plan to manually add some random site into the install whitelist so it can execute its exploit
ajaspers
Sun 8th May '05, 9:48pm
Successful exploitation requires that the site is allowed to install software (default sites are "update.mozilla.org" and "addons.mozilla.org").How is this "extremely critical?"
Zachery
Sun 8th May '05, 10:29pm
Never know what spyware can do ;) modify the hosts files to point the domains at differnt servers. bam, whole can of worms
cirisme
Sun 8th May '05, 10:40pm
How is this "extremely critical?"
Good security is layered, so are better vulnerabilities. ;)
Scott MacVicar
Mon 9th May '05, 6:51am
Err you can visit a site and it will install blah.exe on your machine and run it, to me thats Extremely Critical.
It uses 2 bugs, one is allowing javascript icons as the paramater to the install function for extensions, this is run as Chrome which has full permissions to the system. But there is a white list for sites allowed to install extensions, specifically update.mozilla.org so they found an XSS too using event triggers and history.
But its been blocked now by changing the install function at update.mozilla.org to have 32 random characters in the name.
vBulletin® v3.8.0 Beta 4, Copyright ©2000-2008, Jelsoft Enterprises Ltd.