Firefox Password Manager Vulnerability

I’ve been so busy this past week with work I have not had a chance to keep up on the latest Firefox/Mozilla news. Earlier this week a major vulnerability was exposed for Firefox 1.5.0.8, 2.0, 2.0.0.1pre (not sure about 3.0a1pre) and SeaMonkey 1.0.6:

“A vulnerability in Firefox handling of saved passwords has been announced today. The vulnerability allows Firefox to autofill saved credentials no matter where they are being submitted.

As shown in a test case attached to the relevant bug, as long as similar forms are published in the same web site credentials are retrieved. Robert Chapin, the original reporter, encountered this vulnerability while surfing around MySpace.com, the popular social web site. He visited a user’s profile and was prompted there with a web form resembling MySpace’s typical log on form. Since the form was hosted at MySpace, Firefox autofilled the fake form. A glitch in the fake web form alerted Chapin and saved him from a, somewhat trivial in this case, identity theft.” – Mozilla Links

More technical discussion can be found on Bugzilla (Bug 360493). Also more info on the mozillaZine Firefox Bugs Forum.

As a security precaution it is advisable for users to disable the auto-filling of passwords until this issue is fixed. From the Tools menu, select Options…, on the Security tab, uncheck Remember passwords for sites. At this time I am not sure if this is going to be in the Firefox 1.5.0.9 & 2.0.0.1 updates scheduled for December 14th.

2 Responses to “Firefox Password Manager Vulnerability”


  1. 2 ffextensionguru Saturday, November 25, 2006 at 10:01 PM

    I have heard rumors IE7 was at well. Opera is suppose to be immune to this as it uses a different method for filling passwords.


Leave a Reply




 

November 2006
S M T W T F S
« Oct   Dec »
 1234
567891011
12131415161718
19202122232425
2627282930  

Upcoming Releases

Fx 3.0.12 -- July 21st
Fx 3.0.13 -- September 1st
Fx 3.5.2 -- End July/Early August

Chandler, AZ Weather

Categories

Archives

Blog Stats

  • 769,692 views
Upcoming Releases
- Fx 1.5.0.10/2.0.0.2
RELEASED February 23rd - Major Update (Fx 1.5.0.X to 2.0.0.X)
Mid/Late March - Fx 1.5.0.11/2.0.0.3
March 13 Tentative - Fx 1.5.0.12/2.0.0.4
April 2007 Tentative - Fx 3.0a2/Gecko 1.9a2
RELEASED February 7th - Fx 3.0a3/Gecko 1.9a3
March 19th Tentative - TB 1.5.0.10
RELEASED March 1st - TB 2.0b2
RELEASED January 24th - TB 2.0 (Final)
Late March 2007