Please pardon our mess while we undergo some maintenance changes We are currently updating our website Where the users have the power to submit, vote, and talk about Mozilla and Firefox News, Firefox Extension, Mozilla Development, Mozilla Stories are chosen by the community members and the editors. Get Involved a global community working together
An attacker can use this vulnerability to collect session information, including session cookies and session history. Firefox is not vulnerable by default. Only users that have installed "flat" packed add-ons are at risk. Discussion about "flat" packaged add-ons is here. A partial list of "flat" packed add-ons is available here. If you are an author of any of these add-ons, please release an update to your add-on that uses .jar packaging.
This bug is tracking the additional information: https://bugzilla.mozilla.org/show_bug.cgi?id=413451
Based on this new information Mozilla has changed the security severity rating to high. A fix is included in Firefox 2.0.0.12 which be available shortly.
More From LouCypher
Comments