Web Security News

Mozilla and Microsoft tangle on Firefox plug-in security

Monday, October 19, 2009

Microsoft and Mozilla got their signals crossed last week over a Windows plug-in called .NET Framework Assistant included by Microsoft in the Firefox browser for activation of add-on programs. Mozilla is blocking one vulnerable Microsoft add-on and blocked then unblocked another.

On Friday, Mozilla blocked the .NET Framework Assistant add-on for Firefox 3.5, citing difficulties some users had entirely removing the add-on, "and because of the severity of the risk it represents if not disabled," according to Mike Shaver, Mozilla's vice president of engineering, on the Mozilla security blog.

Shaver said Mozilla contacted Microsoft "to indicate that we were looking to disable the extension and plugin for all users via our blocklisting mechanism," according to the blog post. But on Sunday, Mozilla was trying to unblock the add-on for .NET Framework Assistant, as Shaver said the add-on did not pose a security vulnerability.

"We received confirmation from Microsoft this evening that the Framework Assistant add-on is not a mechanism for exploiting the vulnerabilities detailed in the earlier post, so we've removed it from the blocklist," Shaver said in his blog.

But a separate vulnerability exists for a Microsoft add-on that Mozilla said needs blocking for Firefox users. The vulnerability exists in the Windows Presentation Foundation (WPF), which is included in the .NET Framework Service Pack 1. Shaver said via Twitter that the "WPF plugin is the vector for the XBAP vuln via Firefox."ADNFCR-1765-ID-19415147-ADNFCR

Related News:

Network security concerns prompt postponement of Google phones in China - 1.20.2010
The Wall Street Journal reports that Google has decided to indefinitely postpone the launch of two of its Android smartphones to the Chinese market, which pundits have taken as further proof of the growing rift between the search giant and the Chinese government.

Cloud network security concerns prompt Microsoft to propose new laws - 1.20.2010
Microsoft's general counsel, Brad Smith, told an audience at the Brookings Institution today that the government should step in to regulate the emerging cloud computing industry and help protect businesses and consumers from fraud and abuse.

Network security experts unmask command servers behind Google attack - 1.19.2010
Researchers at VeriSign's iDefense lab have published a report claiming that the Chinese government was responsible for the recent large-scale cyber attacks that targeted Google and other U.S. companies.

Out-of-band IE patch to fix widespread vulnerability - 1.19.2010
Microsoft will issue a patch to its Internet Explorer browser software before its next scheduled update, intended to fix the flaw that enabled hackers to launch a damaging cyber attack on numerous U.S. companies.

France and Germany warn citizens to avoid using Internet Explorer - 1.18.2010
The governments of both France and Germany have issued official warnings to their citizenry, saying that, until Microsoft releases a patch for the widely-used Internet Explorer web browser, it is a threat to network security and should not be used.

View Related Resources
Or
Watch an Online Demo
Or
Have us call you now