Friday, April 6th, 2007
Update Firebug to 1.0.4
Update — go get 1.04 — its a more robust fix for the security issue - read Joe’s comment here.
Joe Hewitt has posted an update to Firebug that you should grab right away as it fixes a couple of issues and covers a 0-day security hole.
The update has been published to addons.mozilla.org, so you can get it by updating Firebug from the Firefox Add-ons window. Alternatively, you can install the update using the big orange button on the getfirebug.com home page.












ouch… this is the blog page that discussed the issue http://www.gnucitizen.org/blog/firebug-goes-evil
Thanks for posting this Dion. :)
/me updates…
How did the article writer know I was a geek?
Wow, that exploit is pretty serious. Once an attacker can control FF chrome from an *extension*, they basically can do whatever they want to the underlying OS. Something about that doesn’t seem quite right.
Time for Firefox to get “Protected Mode”.
Here is the new vulnerability that caused 1.0.4 to be released, together with some thoughts on Chrome security:
http://larholm.com/2007/04/06/more-0day-in-firebug/