Mozilla admits Firefox extension threat
By Matthew Sparkes
Posted on 24 Jan 2008 at 07:58
Mozilla has admitted that a bug in Firefox could allow hackers access to personal data, even if a user is running a fully patched browser.
The vulnerability affects certain extensions, and allows an attacker to probe for files on a user's hard disk.
Some extensions are granted access to specific local directories, but the vulnerability allows code to explore outside of these confines and test for the presence of certain files.
"A visited attacking page is able to load images, scripts, or stylesheets from known locations on the disk. Attackers may use this method to detect the presence of files which may give an attacker information about which applications are installed," says Mozilla security expert, Window Snyder, in a blog post.
This information could give attackers a way to break into a system using known vulnerabilities in other software, warns Snyder.
Users are only at risk if they have one of the "flat" packaged add-ons installed, such as Download Statusbar and Greasemonkey.
Earlier this month it emerged that another security vulnerability in Firefox 18.104.22.168 could be used to trick users into divulging passwords for online services.
Is your business a social business? For helpful info and tips visit our hub.
- 20 years of PC Pro: our best covers
- Why we've closed the PC Pro forums
- How to turn off Google Location Tracking
- 20 years of PC Pro: our greatest review mistakes
- 20 years of PC Pro: our first A-List
- Wikipedia's "right to be forgotten" protest hits the wrong note
- 3D printing hits the high street for plastic selfies
- 20 years of PC Pro: What amazed us in our first issue
- How Google Glass ruined my lunch hour
- Smartphone battery packs: can a USB power pack beat the festival battery blues?
- How to sell more ebooks on Amazon
- 10 ways to make your business more secure
- Top five VoIP mistakes
- How to add in-app purchasing to an iPhone, Android or Windows app
- Remote-control ransomware: TeamViewer and software hardball
- Why laptops with serial ports matter to the Internet of Things
- Make your mobile battery last longer
- Small steps into handling Big Data
- Nexus 5: does it really run stock Android?
- How to get broadband to a garden office