Jump to content
The Inquirer-Home

Mozilla warns of leaky Firefox

Monkey needs greasing, status bar barred
Thursday, 24 January 2008, 12:10

A BOG chez Mozzarella says a vulnerability in Firefox's chrome protocol scheme allows directory traversal when a “flat” add-on is present resulting in potential information disclosure.

Users are only at risk if they have one of the “flat” packaged add-ons installed," apparently. Examples of popular add-ons that are vulnerable include: Download Statusbar and Greasemonkey, says the bog posting.

There's more of this unfathomable stuff here. µ

Share this:

Comments
oh really

what an arse the news desk is. seems they forgot to mention a workaround.

# Giorgio Maone Says:
January 23rd, 2008 at 10:46 am

The NoScript extension prevents chrome: URIs from being loaded as scripts in content pages, effectively making this bug unexploitable no matter if the page is trusted or not.

posted by : hobobill, 24 January 2008 Complain about this comment
No Script . . .

The most important piece of software when browsing the web. Full stop.

Thank you Giorgio Maone!

posted by : Scotty, 25 January 2008 Complain about this comment
it's not that type of leak that's the problem

It's the one that results in me having to kill firefox/thunderbird every so often to reclaim enough memory, page file space and CPU cycles to run other things. 250MB RAM yesterday, with only one instance and 5 tabs (all on a football news site). Been like that for years.

posted by : Chris Melville, 25 January 2008 Complain about this comment
Advertisement
Subscribe to the INQ Newsletter
Sign-up for the INQBot weekly newsletter
Click here to sign up Existing user
Advertisement
INQ Poll

Christmas computer sales

Will you be buying a new computer this Christmas?