Firefox Hands Out Cookies From Strangers

Firefox suffers from a flaw that allows attackers to manipulate the authentication cookies of virtually any website, a vulnerability Bugzilla has deemed severe. It’s the second major security lapse for the open-source browser in as many days.

The defect, which stems from the way Firefox writes to the “location.hostname” property of the document object model, can be exploited by a specially doctored script that sets variables that normally wouldn’t be accepted when parsing a regular URL, according to researcher Michal Zalewski, who uncovered Monday’s vulnerability as well.

View: The full story
News source: The Reg

1 comment

  1. It does make you wonder where IE would be today had Firefox not pushed the envelope. Thats what I like so much about Firefox, I can make it look and act exactly how I prefer. A nice customization guide.

Leave a comment

Your email address will not be published. Required fields are marked *