Browsers - Beware of Flat-Packed Firefox Add-ons - eWeek Security Watch

Beware of Flat-Packed Firefox Add-ons

Written By
Ryan Naraine
Ryan Naraine
Jan 30, 2008
1 minute read
eWeek content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Mozilla has slapped a “high severity” rating on an unpatched Firefox vulnerability that could let hackers steal session cookies — and sensitive user information — from Web surfers.

Mozilla security chief Window Snyder (left) confirmed the issue in a blog entry late Tuesday, warning that Firefox users who have installed “flat” That packed add-ons (browser extensions) are at risk.

The flaw was originally reported as a low-risk information disclosure issue that could help with pre-attack reconnaissance, but Snyder’s latest update confirms the risk is much higher.

“An attacker can use this vulnerability to collect session information, including session cookies and session history,” Snyder said.

[ SEE: Do You Know What’s Leaking Out of Firefox? ]

Stolen cookies and session information could eventually lead to a complete hijack of things such as Gmail accounts, Amazon.com and eBay credentials, and other sensitive Web-based accounts.

Although Firefox is not vulnerable by default (only users who have installed “flat” packed add-ons are at risk), this partial list of vulnerable Firefox extensions is very, very long.

It includes popular add-ons like Greasemonkey, Download Statusbar, Finjan Secure Browsing and YouTube It.

“If you are an author of any of these add-ons, please release an update to your add-on that uses .jar packaging,” Snyder added.

Mozilla plans to ship Firefox 2.0.0.12 very soon — possibly by the end of this week — to patch this vulnerability.

eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.