In association with heise online

05 April 2007, 12:57

New version of firebug fixes vulnerability

  • Twitter
  • Facebook
  • submit to slashdot
  • StumbleUpon
  • submit to reddit

Version 1.03 von Firebug, a high-performance JavaScript debugger for Firefox, closes a hole: code being debugged is run in the browser in the context of chrome, the most highly authorized access privileges. For this to to be exploited, however, malicious JavaScript code must be loaded by the debugger. This rarely occurs, since the Firebug add-on is generally used by developers to test their own programs. If, however, unknown sites are analyzed, as done for example by security specialists, malicious code may slip in. According to the error report, the source of the problem is a function (console.log) of Firebug to print messages to a console. This enables an attacker to print JavaScript code to the console which is executed in the browser with the privileges of chrome:.

see also:

(mba)

Print Version | Send by email | Permalink: http://h-online.com/-732611
 


  • July's Community Calendar





The H Open

The H Security

The H Developer

The H Internet Toolkit