eWeek Security Watch
Advertisement
Advertisement
January 29, 2008 10:46 PM

Beware of Flat-Packed Firefox Add-ons



Beware of Flat-packed Firefox Add-ons Mozilla has slapped a "high severity" rating on an unpatched Firefox vulnerability that could let hackers steal session cookies -- and sensitive user information -- from Web surfers.

Mozilla security chief Window Snyder (left) confirmed the issue in a blog entry late Tuesday, warning that Firefox users who have installed "flat" That packed add-ons (browser extensions) are at risk.

The flaw was originally reported as a low-risk information disclosure issue that could help with pre-attack reconnaissance, but Snyder's latest update confirms the risk is much higher.

"An attacker can use this vulnerability to collect session information, including session cookies and session history," Snyder said.

[ SEE: Do You Know What's Leaking Out of Firefox? ]

Stolen cookies and session information could eventually lead to a complete hijack of things such as Gmail accounts, Amazon.com and eBay credentials, and other sensitive Web-based accounts.

Although Firefox is not vulnerable by default (only users who have installed "flat" packed add-ons are at risk), this partial list of vulnerable Firefox extensions is very, very long.

It includes popular add-ons like Greasemonkey, Download Statusbar, Finjan Secure Browsing and YouTube It.

"If you are an author of any of these add-ons, please release an update to your add-on that uses .jar packaging," Snyder added.

Mozilla plans to ship Firefox 2.0.0.12 very soon -- possibly by the end of this week -- to patch this vulnerability.

TrackBack

TrackBack

http://securitywatch.eweek.com/cgi-bin/mte/mt-tb.cgi/12593

Post a Comment

 
 


RSS Syndication
Advertisement
Advertisement
Security Watch     Contact Us | Advertise | Site Map
Ziff Davis Enterprise

Ziff Davis Enterprise Home | Contact Us | Advertise | Link to Us | Reprints | Magazine Subscriptions | Newsletters
RSS Feeds | White Papers | ROI Calculators | Tech Podcasts | Tech Video |

Baseline | Careers | Channel Insider | CIO Insight | DesktopLinux | DeviceForge | DevSource | eSeminars |
eWEEK | LinuxDevices | Linux Watch | Microsoft Watch | Mid-market | Networking | PDF Zone |
Publish | eWeek Security | Strategic Partner | Web Buyer's Guide | Windows for Devices

Developer Shed | Dev Shed | ASP Free | Dev Articles | Dev Hardware | SEO Chat | Tutorialized | Scripts |
Code Walkers | Web Hosters | Dev Mechanic | Dev Archives | IT Marketplace | igrep

Use of this site is governed by our Terms of Use and Privacy Policy

Copyright ©1996-2007 Ziff Davis Enterprise, Inc. All Rights Reserved. Security Watch is a trademark of Ziff Davis Enterprise, Inc. Reproduction in whole or in part in any form or medium without express written permission of Ziff Davis Enterprise Inc. is prohibited.

Ziff Davis Enterprise