Slashdot Mirror


Password Vulnerability In Firefox 2.0.0.5

Paris The Pirate writes "According to a message posted over the weekend on the Full-Disclosure mailing list, the latest version of Firefox, 2.0.0.5, contains a password management vulnerability that can allow malicious Web sites to steal user passwords. If you have JavaScript enabled and allow Firefox to remember your passwords, you are at risk from this flaw."

3 of 176 comments (clear)

  1. Is this OS independent? by sexybomber · · Score: 4, Interesting

    I haven't RTFA (after all, this is Slashdot), but are all OSes equally vulnerable?

  2. Safari by ens0niq · · Score: 3, Interesting
    1. Re:Safari by pherthyl · · Score: 3, Interesting

      Interestingly enough, Konqueror/KHTML (on which Safari is based) is not vulnerable (just tried the demo). It does password saving as well, but apparently have found a way to avoid the problem.