November 25, 2006

Firefox Password Manager Vulnerability

I’ve been so busy this past week with work I have not had a chance to keep up on the latest Firefox/Mozilla news. Earlier this week a major vulnerability was exposed for Firefox 1.5.0.8, 2.0, 2.0.0.1pre (not sure about 3.0a1pre) and SeaMonkey 1.0.6: “A vulnerability in Firefox handling of saved passwords has been announced today. The vulnerability allows Firefox to autofill saved credentials no matter where they are being submitted. As shown in a test case attached to the relevant bug, as long as similar forms are published in the same web site credentials are retrieved. Robert Chapin, the original…

Read More