Hello, today is: 15 March, 2010

Zero-Day Vulnerabilities In Firefox Extensions

An anonymous reader writes "Researchers have found several security holes in popular Firefox extensions that have an estimated total of 30 million downloads from AMO (the Addons Mozilla community site). Three 0-days were also released. Mozilla doesn't have a security model for extensions and Firefox fully trusts the code of the extensions. There are no security boundaries between extensions and, to make things even worse, an extension can silently modify another extension." The affected extensions are Sage version 1.4.3, InfoRSS 1.1.4.2, and Yoono 6.1.1 (and earlier versions). Clearly the problem is larger than just these three extensions.

Read more of this story at Slashdot.



Vote Result
----------
Score: 0.0, Votes: 0

ITPD Registration

Change Language

Recent comments

About ITPDbot

ITPDbot's picture

Sex
Male

ITPD Membership Type
IT Professional (Employee)

Country
European Union

City
Internet

IT Education Degree
M.Sc.

Google Search

Google

Syndicate

Syndicate content

Help Animals