Password Vulnerability In Firefox 2.0.0.5

Topics Firefox on July 24th, 2007

According to a message posted over the weekend on the Full-Disclosure mailing list, the latest version of , 2.0.0.5, contains a password management vulnerability that can allow malicious sites to steal user . If you have enabled and allow to remember your , you are at risk from this flaw.

The Mozilla team fixed a similar flaw last November, one which did not require . The heise Security site contains a demo/proof of concept of the vulnerability risk that you can use to determine your vulnerability. The original flaw was referred to as reverse cross-site scripting and was reportedly widely used on .com.

Note: A reader has pointed out that .com does not allow , as originally reported. The reader is correct, although there do seem to be workarounds which result in executing on some browsers. Discussions between heise Security and Mozilla developers describe a debate among Mozilla developers over removing this feature, since “evil” server pages can steal from browsers whether the user has opted for password management by or not.

Apple’s Safari is vulnerable in the same way. Current workarounds include disabling in or avoiding the use of password management on sites where users are allowed to post pages.

Share and Enjoy:
  • del.icio.us
  • StumbleUpon
  • Facebook
  • Google
  • Furl
  • Live
  • MisterWong.DE
  • NewsVine
  • Reddit
  • Slashdot
  • Technorati
  • YahooMyWeb
  • BlinkList
  • description
  • Fark
  • Netvouz
  • Spurl
  • MisterWong
  • Webnews.de
  • E-mail this story to a friend!
  • Print this article!

Tags:, , , , , ,

Related posts

4 Responses to “Password Vulnerability In Firefox 2.0.0.5”

  1. 1
    University Update - Firefox - Password Vulnerability In Firefox 2.0.0.5 Says:

    [...] Link to Article firefox Password Vulnerability In Firefox 2.0.0.5 » Posted at PC Tips Box on [...]

  2. 2
    Netscape Says:

    [...] /**/ [...]

  3. 3
    Newsvine - internet Says:

    [IMG Comments][IMG ]

  4. 4
    StumbleUpon » Your page is now on StumbleUpon! Says:

    [...] Your page is on StumbleUpon [...]

Leave a Reply