Vulnerability In Firefox Popup Blocker
cj writes in with news of a vulnerability in Firefox's stock popup blocker discovered by Michal Zalewski. The vulnerability can allow a malicious user to read files from an affected system. The attacker would "need to plant a predictably named file with exploit code on the target system. This sounds hard, but isn't," according to the article.
It takes a man to suffer ignorance and smile
Be yourself no matter what they say
From the fine article:
"When the user chooses to manually allow a blocked popup however, normal URL permission checks are bypassed. "
So you have to MANUALLY disable the popup blocker on a site you don't know in order to make this work. Also, the article keeps talking about c:\whatever. It does not indicate if this is a vulnerability in a non-Windows system.
Already fixed: https://bugzilla.mozilla.org/show_bug.cgi?id=36942 7