Feed script insertion flaw in Firefox 'Sage' extension

Firefox, Thunderbird, SeaMonkey, Camino, Mozilla, Netscape 6/7/8/9, and all Gecko-based browsers discussion and support forum.
(MozInfo701, Netscape Browser Archive)

Moderators: Antony, Edward, profman, Ramona

Do you have Sage extension installed?

Poll ended at Sun 18 Feb, 2007 11:48 am

Yes
0
No votes
No
2
50%
What is Sage...
2
50%
 
Total votes : 4

Feed script insertion flaw in Firefox 'Sage' extension

Postby J-M » Fri 09 Feb, 2007 11:48 am

A patched security vulnerability in Sage extension of Firefox has been reported today.

Link to the security advisory (i.e. warning) of Danish Secunia company:

Firefox Sage Extension Feed Script Insertion Vulnerability

From the Description field:
Fukumori has reported a vulnerability in the Sage extension for Firefox, which can be exploited by malicious people to conduct script insertion attacks.

The vulnerability is caused due to an input validation error in the processing of certain tags in RSS feeds. This can e.g. be exploited to insert and execute arbitrary HTML and script code in a local context by tricking a user into adding a malicious feed and then viewing its contents.

The vulnerability is reported in version 1.3.9. Prior versions may also be affected.


Version 1.3.10 is not affected.

The official page of the Sage entension:
http://sage.mozdev.org/
UserAgent: Mozilla/5.0 (Macintosh; U; PPC Mac OS X Mach-O; en-US; rv:1.8.1.1) Gecko/20061204 Firefox/2.0.0.1
User avatar
J-M
diamond member
diamond member
 
Posts: 815
Joined: Sun 25 Jul, 2004 9:16 am
Location: Helsinki, Finland

Postby Fulvio » Fri 09 Feb, 2007 11:57 am

I almost opted for the third choice. Why Sage?
UserAgent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.1.2pre) Gecko/20070208 BonEcho/2.0.0.2pre
A minority may be right, and a majority is always wrong
~ Henrik Ibsen
WinXP, SP3, 512 MB, SM2.9.1, FF12, TB12.0.1, IE8.0, Google Chrome18, Ghostwall , Avast 7.x, JRE1.7_04. Testing FF13b3
User avatar
Fulvio
Moderator
Moderator
 
Posts: 11914
Joined: Wed 19 Jun, 2002 10:08 am


Return to Firefox, SeaMonkey and Netscape

Who is online

Registered users: Google [Bot], Yahoo [Bot]