<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>

<channel>
	<title>Mozilla Security Blog</title>
	<atom:link href="http://blog.mozilla.com/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.mozilla.com/security</link>
	<description>Window Snyder's Blog</description>
	<pubDate>Wed, 30 Jul 2008 19:33:27 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.2</generator>
	<language>en</language>
			<item>
		<title>Low Risk Denial of Service in Firefox</title>
		<link>http://blog.mozilla.com/security/2008/07/30/low-risk-denial-of-service-in-firefox/</link>
		<comments>http://blog.mozilla.com/security/2008/07/30/low-risk-denial-of-service-in-firefox/#comments</comments>
		<pubDate>Wed, 30 Jul 2008 19:30:51 +0000</pubDate>
		<dc:creator>Window Snyder</dc:creator>
		
		<category><![CDATA[Firefox]]></category>

		<category><![CDATA[Security]]></category>

		<category><![CDATA[Vulnerabilities]]></category>

		<guid isPermaLink="false">http://blog.mozilla.com/security/?p=39</guid>
		<description><![CDATA[Issue
A null pointer dereference in the content layout component of Firefox allows an attacker to crash the browser when a user navigates to a malicious page.
Impact
If a user browses to a malicious page that takes advantage of this vulnerability, the browser will crash.  A feature in Firefox called Session Restore will restore the browser session [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Issue</strong></p>
<p>A null pointer dereference in the content layout component of Firefox allows an attacker to crash the browser when a user navigates to a malicious page.</p>
<p><strong>Impact</strong></p>
<p>If a user browses to a malicious page that takes advantage of this vulnerability, the browser will crash.  A feature in Firefox called Session Restore will restore the browser session when Firefox is restarted and will likely save user typed content in text areas as well.  This feature is designed to save users&#8217; work in the event of a crash or browser restart.</p>
<p><strong>Status</strong></p>
<p>This issue is currently under investigation.  Mozilla has assigned this bug an initial severity rating of low because of the minimal security risk to users.</p>
<p><strong>Credit</strong></p>
<p>Radware reported this issue to Mozilla.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.mozilla.com/security/2008/07/30/low-risk-denial-of-service-in-firefox/feed/</wfw:commentRss>
		</item>
		<item>
		<title>TippingPoint vulnerability patched in Firefox 3.0.1 and 2.0.0.16</title>
		<link>http://blog.mozilla.com/security/2008/07/16/tippingpoint-vulnerability-patched-in-firefox-301-and-20016/</link>
		<comments>http://blog.mozilla.com/security/2008/07/16/tippingpoint-vulnerability-patched-in-firefox-301-and-20016/#comments</comments>
		<pubDate>Wed, 16 Jul 2008 21:15:19 +0000</pubDate>
		<dc:creator>Window Snyder</dc:creator>
		
		<category><![CDATA[Firefox]]></category>

		<category><![CDATA[Security]]></category>

		<category><![CDATA[Vulnerabilities]]></category>

		<guid isPermaLink="false">http://blog.mozilla.com/security/?p=38</guid>
		<description><![CDATA[Issue
A vulnerability in the way Firefox handles CSS allows an attacker to take advantage of an integer overflow and execute arbitrary code.  In order for the attack to be successful a user must browse to a malicious site.  The advisory is available here.
Impact
This critical vulnerability was reported to Mozilla before details were available publicly.  By [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Issue</strong></p>
<p>A vulnerability in the way Firefox handles CSS allows an attacker to take advantage of an integer overflow and execute arbitrary code.  In order for the attack to be successful a user must browse to a malicious site.  The advisory is available <a href="http://www.mozilla.org/security/announce/2008/mfsa2008-34.html">here</a>.</p>
<p><strong>Impact</strong></p>
<p>This critical vulnerability was reported to Mozilla before details were available publicly.  By keeping the details of the issue private until the issue was patched, TippingPoint and Mozilla were able to keep the risk to users minimal.</p>
<p><strong>Status</strong></p>
<p>This issue is patched in Firefox 3.0.1 and 2.0.0.16 which are now available.  Users will be prompted to install the update through the automatic update feature.  If you would like to update now, select &#8220;Check for Updates&#8221; from the Help menu.</p>
<p><strong>Credit</strong></p>
<p>An anonymous reporter found this vulnerability and reported it to TippingPoint.  TippingPoint reported it to Mozilla.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.mozilla.com/security/2008/07/16/tippingpoint-vulnerability-patched-in-firefox-301-and-20016/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Mozilla Security Metrics Project</title>
		<link>http://blog.mozilla.com/security/2008/07/02/mozilla-security-metrics-project/</link>
		<comments>http://blog.mozilla.com/security/2008/07/02/mozilla-security-metrics-project/#comments</comments>
		<pubDate>Thu, 03 Jul 2008 00:10:17 +0000</pubDate>
		<dc:creator>Window Snyder</dc:creator>
		
		<category><![CDATA[Announcements]]></category>

		<category><![CDATA[Firefox]]></category>

		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://blog.mozilla.com/security/?p=37</guid>
		<description><![CDATA[Mozilla has been working with security researcher and analyst Rich Mogull for a few months now on a project to develop a metrics model to measure the relative security of Firefox over time. We are trying to develop a model that goes beyond simple bug counts and more accurately reflects both the effectiveness of secure [...]]]></description>
			<content:encoded><![CDATA[<p>Mozilla has been working with security researcher and analyst <a href="http://securosis.com/about/">Rich Mogull</a> for a few months now on a project to develop a metrics model to measure the relative security of Firefox over time. We are trying to develop a model that goes beyond simple bug counts and more accurately reflects both the effectiveness of secure development efforts, and the relative risk to users over time. Our goal in this first phase of the project is to build a baseline model we can evolve over time as we learn what works, and what does not. We do not think any model can define an absolute level of security, so we decided to take the approach of tracking metrics over time so we can track relative improvements (or declines), and identify any problem spots.  This information will support the development of Mozilla projects including future versions of Firefox.</p>
<p>Below is a summary of the project goals, and the xls of the model is posted at <span class="Object"><span class="Object"><a href="http://securosis.com/publications/MozillaProject2.xls" target="_blank">http://securosis.com/publications/MozillaProject2.xls</a></span></span>.  The same content as a set of .csvs is available here: <a href="http://securosis.com/publications/MozillaProject.zip">http://securosis.com/publications/MozillaProject.zip</a> [Update] There also a copy for OpenOffice:<span class="Object"><a href="http://securosis.com/publications/MozillaProject2.ods" target="_blank"> http://securosis.com/publications/MozillaProject2.ods</a></span></p>
<p>This is a preliminary version and we are currently looking for feedback. The final version will be a far more descriptive document, but for now we are using a spreadsheet to refine the approach. Feel free to download it, rip it apart, and post your comments. This is an open project and process.  Eventually we will release this to the community at large with the hope that other organizations can adapt it to their own needs.</p>
<p>We would love to get your opinions on this, and if you are not comfortable commenting here you can mail Rich directly at <span class="Object"><span class="Object">rmogull@securosis.com</span></span>.  When we have reviewed the feedback, we will post here with findings and continue the effort with your help.</p>
<p>Project Mission:<br />
To develop a metrics based model to track the relative security of Firefox, evaluate the effectiveness of security efforts within the development and testing process, and measure the window of exposure of Firefox users to security vulnerabilities.</p>
<p>Secondary mission:<br />
To develop an open base model that can be standardized and expanded upon for other software development efforts to achieve the same goals.</p>
<p>Detailed goals:<br />
1. Track security trends in the development of Firefox.<br />
2. Measure the effectiveness of various tools, stages and techniques of secure development.<br />
3. Measure the exposure window when new vulnerabilities are discovered- the time to get x% of the user base protected. Will include sub-metrics to measure the efficiency of the process, from initial response, through patch generation, through user base updated.  Correlate by severity of vulnerability.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.mozilla.com/security/2008/07/02/mozilla-security-metrics-project/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Firefox users most likely to run latest version of the browser</title>
		<link>http://blog.mozilla.com/security/2008/07/02/firefox-users-most-likely-to-run-latest-version-of-the-browser/</link>
		<comments>http://blog.mozilla.com/security/2008/07/02/firefox-users-most-likely-to-run-latest-version-of-the-browser/#comments</comments>
		<pubDate>Wed, 02 Jul 2008 18:14:08 +0000</pubDate>
		<dc:creator>Window Snyder</dc:creator>
		
		<category><![CDATA[Firefox]]></category>

		<category><![CDATA[Press]]></category>

		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://blog.mozilla.com/security/?p=36</guid>
		<description><![CDATA[A recent report identified  Firefox users as most likely to be running the latest version of the browser at any point in time.  Brian Krebs at the Washington Post comments on it here: Forty Percent of Web Users Surf With Unsafe Browsers
This is great news for Mozilla, since it demonstrates that the work that [...]]]></description>
			<content:encoded><![CDATA[<p>A <a href="http://www.techzoom.net/publications/insecurity-iceberg/index.en">recent report</a> identified  Firefox users as most likely to be running the latest version of the browser at any point in time.  Brian Krebs at the Washington Post comments on it here: <a href="http://blog.washingtonpost.com/securityfix/2008/07/40_percent_of_web_users_surf_w_1.html?nav=rss_blo">Forty Percent of Web Users Surf With Unsafe Browsers</a></p>
<p>This is great news for Mozilla, since it demonstrates that the work that has gone into the auto update mechanism and the restore session feature has really paid off.  In order to reduce the window of risk for users and minimize the <a href="http://blog.mozilla.com/security/2007/06/18/time-to-deploy-improvement-of-25-percent/">time to deploy</a>, we have put a lot of effort into making sure that it is as easy to install security updates as possible.  This is not the first time <a href="http://blog.mozilla.com/security/2008/01/17/read-past-the-headlines-firefox-is-fixed-faster/">we have heard this</a>, but it is great to get more numbers behind what we already know:  Firefox is safer because Mozilla continually works on security improvements, ships updates quickly, and makes it easier to stay up-to-date.</p>
<p>You will be hearing more about our effort to collect meaningful security metrics like these soon.</p>
<p>Asa has a few words to say about this on <a href="http://weblogs.mozillazine.org/asa/archives/2008/07/staying_up_to_d.html">his blog</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.mozilla.com/security/2008/07/02/firefox-users-most-likely-to-run-latest-version-of-the-browser/feed/</wfw:commentRss>
		</item>
		<item>
		<title>New Security Issue Under Investigation</title>
		<link>http://blog.mozilla.com/security/2008/06/18/new-security-issue-under-investigation/</link>
		<comments>http://blog.mozilla.com/security/2008/06/18/new-security-issue-under-investigation/#comments</comments>
		<pubDate>Thu, 19 Jun 2008 04:07:07 +0000</pubDate>
		<dc:creator>Window Snyder</dc:creator>
		
		<category><![CDATA[Firefox]]></category>

		<category><![CDATA[Security]]></category>

		<category><![CDATA[Vulnerabilities]]></category>

		<guid isPermaLink="false">http://blog.mozilla.com/security/?p=35</guid>
		<description><![CDATA[TippingPoint ZDI notified Mozilla of a vulnerability in Firefox that impacts versions 2.x and 3.0.  This issue is currently under investigation.  To protect our users, the details of the issue will remain closed until a patch is made available.  There is no public exploit, the details are private, and so the current risk to users [...]]]></description>
			<content:encoded><![CDATA[<p>TippingPoint ZDI notified Mozilla of a vulnerability in Firefox that impacts versions 2.x and 3.0.  This issue is currently under investigation.  To protect our users, the details of the issue will remain closed until a patch is made available.  There is no public exploit, the details are private, and so the current risk to users is minimal.</p>
<p>TippingPoint will also keep the details closed to protect Firefox users.  From <a href="http://dvlabs.tippingpoint.com/blog/2008/06/18/vulnerability-in-mozilla-firefox-30">their blog post</a>:</p>
<blockquote><p>While Mozilla is working on a fix, we wont be divulging anything else until a patch is available, adhering to our vulnerability disclosure policy.  Once the issue is patched, we&#8217;ll be publishing an advisory <a href="http://www.zerodayinitiative.com/advisories/published/">here</a>. Working with Mozilla on past security issues, we&#8217;ve found them to have a good track record and expect a reasonable turnaround on this issue as well.</p></blockquote>
<p>At Mozilla we appreciate any report of security issues because that is how we make the browser stronger and more secure.  The best way to keep Firefox users safe is to report the issues directly to Mozilla as TippingPoint has chosen to, and to wait to release details until a fix is available.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.mozilla.com/security/2008/06/18/new-security-issue-under-investigation/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Clarification on Vietnamese Language Pack Compromise</title>
		<link>http://blog.mozilla.com/security/2008/05/12/clarification-on-vietnamese-langauage-pack-compromise/</link>
		<comments>http://blog.mozilla.com/security/2008/05/12/clarification-on-vietnamese-langauage-pack-compromise/#comments</comments>
		<pubDate>Mon, 12 May 2008 09:16:24 +0000</pubDate>
		<dc:creator>Window Snyder</dc:creator>
		
		<category><![CDATA[Firefox]]></category>

		<category><![CDATA[Security]]></category>

		<category><![CDATA[Vulnerabilities]]></category>

		<guid isPermaLink="false">http://blog.mozilla.com/security/2008/05/09/clarification-on-vietnamese-langauage-pack-compromise/</guid>
		<description><![CDATA[As today’s headlines confirm, there is still a lot of confusion about what happened to the Vietnamese language pack, who is impacted, and what that impact really is.
First of all, there is no virus in the Vietnamese language pack. Vietnamese language pack for Firefox users have not been infected with a virus.  The remnant we [...]]]></description>
			<content:encoded><![CDATA[<p>As today’s headlines confirm, there is still a lot of confusion about what happened to the Vietnamese language pack, who is impacted, and what that impact really is.</p>
<p>First of all, there is no virus in the Vietnamese language pack. Vietnamese language pack for Firefox users have not been infected with a virus.  The remnant we detected is a line in an html file that would display ads to users.  This does not infect the user’s machine with the virus.  It is a remnant from a virus that most likely infected the language pack developer’s machine. This code remnant is not present in other language packs.  The entire add-ons site has been scanned for malware and viruses and nothing else has been detected. Disabling the language pack in the add-ons dialog disables the code remnant.</p>
<p>Mozilla scans all add-ons for viruses at upload time, but the nature of most anti-virus software is that it only finds the things it knows how to look for.  When this add-on was uploaded there was no signature in the anti-virus software to detect this virus or its remnants.</p>
<p>There have been 16,667 downloads of the Vietnamese language pack since November 2007. It is hard to identify exactly how many users were impacted, but there are on average about 1000 active users.  While the number of users is small, this is still unacceptable.  We take this issue very seriously.  The most likely impact for users was the display of unwanted ads.</p>
<p>These are the steps we have taken to protect users in the future:</p>
<p>•    The add-ons site was immediately scanned for the presence of viruses and other potential malware, and nothing further has been detected.</p>
<p>•    As a response to this issue and to minimize the potential of something similar happening in the future, Mozilla is now scanning all add-ons whenever the signatures for the anti-virus software are updated.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.mozilla.com/security/2008/05/12/clarification-on-vietnamese-langauage-pack-compromise/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Compromised file in Vietnamese Language Pack for Firefox 2</title>
		<link>http://blog.mozilla.com/security/2008/05/07/compromised-file-in-vietnamese-language-pack-for-firefox-2/</link>
		<comments>http://blog.mozilla.com/security/2008/05/07/compromised-file-in-vietnamese-language-pack-for-firefox-2/#comments</comments>
		<pubDate>Wed, 07 May 2008 20:28:46 +0000</pubDate>
		<dc:creator>Window Snyder</dc:creator>
		
		<category><![CDATA[Firefox]]></category>

		<category><![CDATA[Security]]></category>

		<category><![CDATA[Vulnerabilities]]></category>

		<guid isPermaLink="false">http://blog.mozilla.com/security/2008/05/07/compromised-file-in-vietnamese-language-pack-for-firefox-2/</guid>
		<description><![CDATA[The Vietnamese language pack for Firefox 2 contains inserted code to load remote content.  This code is the result of a virus infection, but does not contain the virus itself.  This usually results in the user seeing unwanted ads, but may be used for more malicious actions.
Everyone who downloaded the most recent Vietnamese language pack [...]]]></description>
			<content:encoded><![CDATA[<p>The Vietnamese language pack for Firefox 2 contains inserted code to load remote content.  This code is the result of a virus infection, but does not contain the virus itself.  This usually results in the user seeing unwanted ads, but may be used for more malicious actions.</p>
<p>Everyone who downloaded the most recent Vietnamese language pack since February 18, 2008 got an infected copy.  While we cannot determine the exact number of compromised downloads, there have been 16,667 total downloads of the Vietnamese language pack since November 2007, so we anticipate the impact on users to be limited.</p>
<p>Mozilla does virus scans at upload time but the virus scanner did not catch this issue until several months after the upload.  We are also adding after-the-fact scans of everything to address this sort of case in the future.</p>
<p>A new language pack will be available shortly.  Until then, Vietnamese language pack users should disable this package using the add-ons dialog on the Tools menu.</p>
<p>More information is available in bugzilla:<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=432406"> https://bugzilla.mozilla.org/show_bug.cgi?id=432406 </a></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.mozilla.com/security/2008/05/07/compromised-file-in-vietnamese-language-pack-for-firefox-2/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Firefox 2.0.0.12 is now available</title>
		<link>http://blog.mozilla.com/security/2008/02/08/firefox-2.0.0.12-is-now-available/</link>
		<comments>http://blog.mozilla.com/security/2008/02/08/firefox-2.0.0.12-is-now-available/#comments</comments>
		<pubDate>Fri, 08 Feb 2008 13:38:37 +0000</pubDate>
		<dc:creator>Window Snyder</dc:creator>
		
		<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://blog.mozilla.com/security/2008/02/08/firefox-2.0.0.12-is-now-available/</guid>
		<description><![CDATA[Firefox 2.0.0.12 is now available.  This security update addresses the directory traversal issue described here and here.  Details for this release are available at: http://www.mozilla.org/projects/security/known-vulnerabilities.html#firefox2.0.0.12
]]></description>
			<content:encoded><![CDATA[<p>Firefox 2.0.0.12 is now available.  This security update addresses the directory traversal issue described <a href="http://blog.mozilla.com/security/2008/01/22/chrome-protocol-directory-traversal/">here</a> and <a href="http://blog.mozilla.com/security/2008/01/29/status-update-for-chrome-protocol-directory-traversal-issue/">here</a>.  Details for this release are available at: <a href="http://www.mozilla.org/projects/security/known-vulnerabilities.html#firefox2.0.0.12">http://www.mozilla.org/projects/security/known-vulnerabilities.html#firefox2.0.0.12</a></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.mozilla.com/security/2008/02/08/firefox-2.0.0.12-is-now-available/feed/</wfw:commentRss>
		</item>
		<item>
		<title>Status update for Chrome Protocol Directory Traversal issue</title>
		<link>http://blog.mozilla.com/security/2008/01/29/status-update-for-chrome-protocol-directory-traversal-issue/</link>
		<comments>http://blog.mozilla.com/security/2008/01/29/status-update-for-chrome-protocol-directory-traversal-issue/#comments</comments>
		<pubDate>Wed, 30 Jan 2008 00:33:29 +0000</pubDate>
		<dc:creator>Window Snyder</dc:creator>
		
		<category><![CDATA[Firefox]]></category>

		<category><![CDATA[Security]]></category>

		<category><![CDATA[Security Updates]]></category>

		<category><![CDATA[Vulnerabilities]]></category>

		<guid isPermaLink="false">http://blog.mozilla.com/security/2008/01/29/status-update-for-chrome-protocol-directory-traversal-issue/</guid>
		<description><![CDATA[Background on this issue is available here.
Impact
An attacker can use this vulnerability to collect session information, including session cookies and session history.  Firefox is not vulnerable by default.  Only users that have installed &#8220;flat&#8221; packed add-ons are at risk.  Discussion about &#8220;flat&#8221; packaged add-ons is here.  A partial list of &#8220;flat&#8221; packed add-ons is available [...]]]></description>
			<content:encoded><![CDATA[<p>Background on this issue is available <a href="http://blog.mozilla.com/security/2008/01/22/chrome-protocol-directory-traversal/">here</a>.</p>
<p><strong>Impact</strong></p>
<p>An attacker can use this vulnerability to collect session information, including session cookies and session history.  Firefox is not vulnerable by default.  Only users that have installed &#8220;flat&#8221; packed add-ons are at risk.  Discussion about &#8220;flat&#8221; packaged add-ons is <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=413549">here</a>.  A partial list of &#8220;flat&#8221; packed add-ons is available <a href="https://bugzilla.mozilla.org/attachment.cgi?id=300181">here</a>.  If you are an author of any of these add-ons, please release an update to your add-on that uses .jar packaging.</p>
<p>This bug is tracking the additional information: <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=413451"></a></p>
<p><a href="https://bugzilla.mozilla.org/show_bug.cgi?id=413451">https://bugzilla.mozilla.org/show_bug.cgi?id=413451 </a></p>
<p><strong>Status</strong></p>
<p>Based on this new information Mozilla has changed the security severity rating to high.  A fix is included in Firefox 2.0.0.12 which be available shortly.<br />
<a href="https://bugzilla.mozilla.org/show_bug.cgi?id=413250"></a></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.mozilla.com/security/2008/01/29/status-update-for-chrome-protocol-directory-traversal-issue/feed/</wfw:commentRss>
		</item>
		<item>
		<title>chrome protocol directory traversal</title>
		<link>http://blog.mozilla.com/security/2008/01/22/chrome-protocol-directory-traversal/</link>
		<comments>http://blog.mozilla.com/security/2008/01/22/chrome-protocol-directory-traversal/#comments</comments>
		<pubDate>Tue, 22 Jan 2008 23:06:41 +0000</pubDate>
		<dc:creator>Window Snyder</dc:creator>
		
		<category><![CDATA[Firefox]]></category>

		<category><![CDATA[Security]]></category>

		<category><![CDATA[Vulnerabilities]]></category>

		<guid isPermaLink="false">http://blog.mozilla.com/security/2008/01/22/chrome-protocol-directory-traversal/</guid>
		<description><![CDATA[Issue
A vulnerability in the chrome protocol scheme allows directory traversal when a &#8220;flat&#8221; add-on is present resulting in potential information disclosure.
Impact
When a chrome package is &#8220;flat&#8221; rather than contained in a .jar the directory traversal allows escaping the extensions directory and reading files in a predictable location on the disk.  Many add-ons are packaged in [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Issue</strong><br />
A vulnerability in the chrome protocol scheme allows directory traversal when a &#8220;flat&#8221; add-on is present resulting in potential information disclosure.</p>
<p><strong>Impact</strong><br />
When a chrome package is &#8220;flat&#8221; rather than contained in a .jar the directory traversal allows escaping the extensions directory and reading files in a predictable location on the disk.  Many add-ons are packaged in this way.</p>
<p>A visited attacking page is able to load images, scripts, or stylesheets from known locations on the disk.  Attackers may use this method to detect the presence of files which may give an attacker information about which applications are installed.  This information may be used to profile the system for a different kind of attack.</p>
<p>Some extensions may store information in Javascript files and an attacker may be able to retrieve those.  Greasemonkey user scripts may be retrieved using this method.  Session storage and preferences are not readable through this technique.</p>
<p>Users are only at risk if they have one of the &#8220;flat&#8221; packaged add-on installed.  Examples of popular add-ons that are vulnerable include: Download Statusbar and Greasemonkey.</p>
<p><strong>Status</strong></p>
<p>Mozilla is currently investigating this information disclosure issue and has assigned it an initial severity rating of low.  Details are available at:  <a href="https://bugzilla.mozilla.org/show_bug.cgi?id=413250">https://bugzilla.mozilla.org/show_bug.cgi?id=413250</a></p>
<p><strong>Credit</strong></p>
<p>Gerry Eisenhaur first posted details of this issue along with proof of concept code at <a href="http://www.hiredhacker.com/2008/01/19/firefox-chrome-url-handling-directory-traversal/">http://www.hiredhacker.com/2008/01/19/firefox-chrome-url-handling-directory-traversal/</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.mozilla.com/security/2008/01/22/chrome-protocol-directory-traversal/feed/</wfw:commentRss>
		</item>
	</channel>
</rss>
