Original URL: http://www.channelregister.co.uk/2008/01/24/firefox_data_leakage_bug/
Mozilla's chief of security has confirmed a vulnerability that could cause fully patched versions of Firefox to expose a user's private data.
The confirmation, which was posted here (http://blog.mozilla.com/security/2008/01/22/chrome-protocol-directory-traversal/) by Mozilla's Window Snyder, follows the release of proof-of-concept code by researcher Gerry Eisenhaur.
The bug resides in Firefox's chrome protocol scheme and allows for a directory traversal when certain types of extensions are installed. Attackers could use it to detect if certain programs or files are present on a machine, gaining information to use in perpetrating another, more malicious exploit.
Normally, Firefox's chrome package is restricted to a limited number of directories, but a bug in the way it handles escaped sequences (i.e. %2e%2e%2f) allows attackers to escape those confines and access more sensitive parts of a user's computer. The exploit only works if a user has made use of Firefox extensions that are "flat," this is, those that don't package their files in a jar archive. Examples of flat add-ons include Download Statusbar and Greasemonkey.
Mozilla bug squashers have rated the severity as normal and are working on a fix. In the meantime, Firefox users can protect themselves by using the NoScript (http://noscript.net/) extension, which will prevent the traversal attacks from working. ®
Story updated to correct information about NoScript.
Firefox developers tinker with new security protections (finally) (20 May 2008)
http://www.channelregister.co.uk/2008/05/20/new_firefox_security_protections/
Firefox language pack provides adware back-door (8 May 2008)
http://www.channelregister.co.uk/2008/05/08/firefox_component_compromise/
Opera screeches at Mozilla over security disclosure (18 February 2008)
http://www.channelregister.co.uk/2008/02/18/opera_moz_security_disclosure_row/
Firefox 3 beta is live (13 February 2008)
http://www.channelregister.co.uk/2008/02/13/firefox_3_beta/
Firefox updates, blitzes trio of critical bugs (8 February 2008)
http://www.channelregister.co.uk/2008/02/08/firefox_update/
Mozilla pulls offensive viral campaign (8 January 2008)
http://www.channelregister.co.uk/2008/01/08/mozilla_pulls_viral_campaign/
Contest seeks the most diminutive XSS worm (5 January 2008)
http://www.channelregister.co.uk/2008/01/05/worm_replication_contest/
Firefox spoofing bug raises phishing fears (4 January 2008)
http://www.channelregister.co.uk/2008/01/04/firefox_spoofing_bug/
Beware of pickpockets and malware-laced banner ads (4 January 2008)
http://www.channelregister.co.uk/2008/01/04/malware_laced_banners/
Serious Flash vulns menace at least 10,000 websites (21 December 2007)
http://www.channelregister.co.uk/2007/12/21/flash_vulnerability_menace/
© Copyright 2008