The Extensions manager in Mozilla Firefox 2.0 does not properly populate the list of local extensions, which allows attackers to construct an extension that hides itself by finding its name in the list and then calling RemoveElement, as demonstrated by the FFsniFF extension. NOTE: it was later reported that 3.0 is also affected.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 00:23
Type | Values Removed | Values Added |
---|---|---|
References | () http://azurit.elbiahosting.sk/ffsniff/ffsniff-0.2.tar.gz - | |
References | () http://securityreason.com/securityalert/2046 - | |
References | () http://www.securityfocus.com/archive/1/454058/100/0/threaded - | |
References | () http://www.securityfocus.com/archive/1/493585/100/0/threaded - |
Information
Published : 2006-12-15 19:28
Updated : 2024-11-21 00:23
NVD link : CVE-2006-6585
Mitre link : CVE-2006-6585
CVE.ORG link : CVE-2006-6585
JSON object : View
Products Affected
mozilla
- firefox
CWE