<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Web Browser News and Reviews &#187; Vulnerability</title>
	<atom:link href="http://www.favbrowser.com/tag/vulnerability/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.favbrowser.com</link>
	<description>Web Browser News and Reviews.</description>
	<lastBuildDate>Sat, 11 Feb 2012 07:26:47 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.1.4</generator>
		<item>
		<title>Google Chrome Download Vulnerability</title>
		<link>http://www.favbrowser.com/google-chrome-download-vulnerability/</link>
		<comments>http://www.favbrowser.com/google-chrome-download-vulnerability/#comments</comments>
		<pubDate>Thu, 04 Sep 2008 08:44:12 +0000</pubDate>
		<dc:creator>Vygantas Lipskas</dc:creator>
				<category><![CDATA[Google Chrome]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Chrome]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[Vulnerability]]></category>

		<guid isPermaLink="false">http://www.favbrowser.com/google-chrome-download-vulnerability/</guid>
		<description><![CDATA[US-CERT is aware of a vulnerability that affects the Google Chrome web browser. This vulnerability is due to a default configuration that allows files to be downloaded without prompting the user. In addition, downloaded files can be opened with a single click, which could allow a user to inadvertently open a malicious file. US-CERT encourages [...]]]></description>
			<content:encoded><![CDATA[<p><img src="http://www.favbrowser.com/images/google-chrome.gif" alt="Google Chrome Download Vulnerability" border="0" width="128" height="128" align="right" />US-CERT is aware of a vulnerability that affects the Google Chrome web browser. This vulnerability is due to a default configuration that allows files to be downloaded without prompting the user. In addition, downloaded files can be opened with a single click, which could allow a user to inadvertently open a malicious file.</p>
<p>US-CERT encourages users to enable the &#8220;Ask where to save each file before downloading&#8221; option within the &#8220;Minor Tweaks&#8221; tab in the browser preferences. <span id="more-484"></span>Although this does not fix the underlying vulnerability, selecting this option will warn the user before files are downloaded. Users should still exercise caution when visiting and downloading items from untrusted websites.</p>
<p>Source: <a href="http://www.us-cert.gov/current/">US-CERT</a></p>
<p>[digg-reddit-me]
<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.favbrowser.com%2Fgoogle-chrome-download-vulnerability%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.favbrowser.com%2Fgoogle-chrome-download-vulnerability%2F&amp;source=favbrowser&amp;style=normal&amp;service=bit.ly&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
]]></content:encoded>
			<wfw:commentRss>http://www.favbrowser.com/google-chrome-download-vulnerability/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Firefox 2.0.0.12 to Fix Chrome Protocol Directory Traversal Vulnerability</title>
		<link>http://www.favbrowser.com/firefox-20012-to-fix-chrome-protocol-directory-traversal-vulnerability/</link>
		<comments>http://www.favbrowser.com/firefox-20012-to-fix-chrome-protocol-directory-traversal-vulnerability/#comments</comments>
		<pubDate>Wed, 30 Jan 2008 12:41:21 +0000</pubDate>
		<dc:creator>Vygantas Lipskas</dc:creator>
				<category><![CDATA[Firefox]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Vulnerability]]></category>

		<guid isPermaLink="false">http://www.favbrowser.com/firefox-20012-to-fix-chrome-protocol-directory-traversal-vulnerability/</guid>
		<description><![CDATA[The upcoming Firefox 2.0.0.12 release will fix this flaw. It affects extensions (more than 600) which are installed as a set of uncompressed files instead of widely used .jar files. Issue A vulnerability in the chrome protocol scheme allows directory traversal when a “flat” add-on is present resulting in potential information disclosure. Impact When a [...]]]></description>
			<content:encoded><![CDATA[<p><img ALIGN="right" HEIGHT="128" WIDTH="128" BORDER="0" ALT="Firefox 2.0.0.12" SRC="http://www.favbrowser.com/images/firefox.gif" />The upcoming Firefox 2.0.0.12 release will fix this flaw. It affects extensions (<a target="_blank" href="https://bugzilla.mozilla.org/attachment.cgi?id=300181">more than 600</a>) which are installed as a set of uncompressed files instead of widely used .jar files.</p>
<p><strong>Issue</strong><br />
A vulnerability in the chrome protocol scheme allows directory traversal when a “flat” add-on is present resulting in potential information disclosure.</p>
<p><strong>Impact</strong><span id="more-273"></span><br />
When a chrome package is “flat” rather than contained in a .jar the directory traversal allows escaping the extensions directory and reading files in a predictable location on the disk.  Many add-ons are packaged in this way.</p>
<p>A visited attacking page is able to load images, scripts, or stylesheets from known locations on the disk.  Attackers may use this method to detect the presence of files which may give an attacker information about which applications are installed.  This information may be used to profile the system for a different kind of attack.</p>
<p>Some extensions may store information in Javascript files and an attacker may be able to retrieve those.  Greasemonkey user scripts may be retrieved using this method.  Session storage and preferences are not readable through this technique.</p>
<p>Users are only at risk if they have one of the “flat” packaged add-on installed.  Examples of popular add-ons that are vulnerable include: Download Statusbar and Greasemonkey.<br />
Source: <a HREF="http://blog.mozilla.com/security/2008/01/22/chrome-protocol-directory-traversal/" TARGET="_blank">blog.mozilla.org</a></p>
<p>Web Browsers News. <a TARGET="_blank" HREF="http://feeds.feedburner.com/FavoriteBrowser">Subscribe to our RSS Feed</a>.
<div class="tweetmeme_button" style="float: right; margin-left: 10px;">
			<a href="http://api.tweetmeme.com/share?url=http%3A%2F%2Fwww.favbrowser.com%2Ffirefox-20012-to-fix-chrome-protocol-directory-traversal-vulnerability%2F"><br />
				<img src="http://api.tweetmeme.com/imagebutton.gif?url=http%3A%2F%2Fwww.favbrowser.com%2Ffirefox-20012-to-fix-chrome-protocol-directory-traversal-vulnerability%2F&amp;source=favbrowser&amp;style=normal&amp;service=bit.ly&amp;b=2" height="61" width="50" /><br />
			</a>
		</div>
]]></content:encoded>
			<wfw:commentRss>http://www.favbrowser.com/firefox-20012-to-fix-chrome-protocol-directory-traversal-vulnerability/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>

