PDA

View Full Version : Mozilla Firefox "locations.hostname" DOM Property Handling Vulnerability


tlu
February 22nd, 2007, 06:51 AM
The well-known security expert Michal Zalewski found a new Firefox vulnerability described on http://lcamtuf.coredump.cx/ffbook/#

The problem is already discussed on Bugzilla (https://bugzilla.mozilla.org/show_bug.cgi?id=371179)

The extension Noscript, which has often been recommended here in the forum, is a good protection against this new vulnerability.

tlu
February 23rd, 2007, 03:03 AM
-{ Quote: " Mozilla Working On Fix For Firefox Flaw Article (http://www.informationweek.com/story/showArticle.jhtml?articleID=197008167)" }-

Ron, you merged my posting into this thread. That's okay - I just want to make sure that this is another vulnerability. It's probably advisable to forbid bookmarklets in Noscript as a countermeasure.

ronjor
February 23rd, 2007, 05:37 AM
-{ Quote: "merged " }-My error Thomas. It is a separate issue. Post restored.