Want to read Slashdot from your mobile device? Point it at m.slashdot.org and keep reading!

 



Forgot your password?
typodupeerror
×
Bug Security Mozilla Technology

Zero-Day Vulnerabilities In Firefox Extensions 208

An anonymous reader writes "Researchers have found several security holes in popular Firefox extensions that have an estimated total of 30 million downloads from AMO (the Addons Mozilla community site). Three 0-days were also released. Mozilla doesn't have a security model for extensions and Firefox fully trusts the code of the extensions. There are no security boundaries between extensions and, to make things even worse, an extension can silently modify another extension." The affected extensions are Sage version 1.4.3, InfoRSS 1.1.4.2, and Yoono 6.1.1 (and earlier versions). Clearly the problem is larger than just these three extensions.
This discussion has been archived. No new comments can be posted.

Zero-Day Vulnerabilities In Firefox Extensions

Comments Filter:
  • by Anonymous Coward on Friday November 20, 2009 @11:25AM (#30171436)

    This is why Microsoft should turn off Activex Controls altogether.........oh wait........

  • by Anonymous Coward on Friday November 20, 2009 @11:32AM (#30171524)

    I'll be switching my law firm back to IE and looking into a lawsuit against all FF contributors for their grossly negligent behavior

    Okay, Jack [wikipedia.org]. Let us know how you make out.

  • by clone53421 ( 1310749 ) on Friday November 20, 2009 @11:39AM (#30171636) Journal

    I thought you were trolling, and then I read this:

    I'll be switching my law firm back to IE and looking into a lawsuit against all FF contributors for their grossly negligent behavior.

    Poe’s Law [rationalwiki.com] appears to be in full effect today.

  • by NoYob ( 1630681 ) on Friday November 20, 2009 @11:52AM (#30171804)

    I will have to go back to using linx now because I trust nothing else...

    If you're that paranoid — use a virtual machine to browse the web and rollback to a trusted, clean snapshot a few times a day.

    Yeah, but how do I know that the snapshot is clean? Or for that matter how do I know that my virtual machine hasn't been compromised?

    They could have put a chip in my brain that makes my think that I'm browsing securely but in fact I'm not!

    And who are you to be posting these things to make us feel like we can be secure? The sig of yours is French, no? But your user name looks Arabic. You could be a French secret agent with an Arabic code name - or, an Islamic Jihadist, hiding in France acting like a friendly internet user "helping" folks to "secure" their browsing habits all along undermining their computers so you and your agents can break in, compromise their machines, do your nefarious activities, and all the while, the poor sap who follows your advice gets arrested by the FBI while you take off with the hot secret agent babes from Russia.

    No sir! I know what you're doing here!

  • by clone53421 ( 1310749 ) on Friday November 20, 2009 @12:08PM (#30172002) Journal

    You can’t possibly be serious...

  • by Anonymous Coward on Friday November 20, 2009 @12:10PM (#30172034)
    Can't find string terminator '"' anywhere before EOF on line 1
  • by unix1 ( 1667411 ) on Friday November 20, 2009 @12:24PM (#30172252)

    They could have put a chip in my brain that makes my think that I'm browsing securely but in fact I'm not!

    So, you have hardwired your brain into your computer and are using it as a Firefox extension? This makes my head spin.

Never test for an error condition you don't know how to handle. -- Steinbach

Working...