The Mozilla Foundation is making available an update for a critical security flaw in Greasemonkey, an extension to the Firefox browser.
Greasemonkey is a popular add-on used to customize the design and behavior of Web pages. The flaw could let attackers read any file on a user's local hard drive and list the contents of local directories. The update, Greasemonkey 0.3.5, was released Monday, according to the download page on the Mozilla Foundation's Web site. The Mozilla Foundation coordinates Firefox development and marketing.
The flaw affects versions of Greasemonkey prior to 0.3.5, including early 0.4 alphas, according to a posting on Mozdev.org, a site where developers post applications and add-ons.
People who switch to version 0.3.5, however, will find it lacks the so-called GM* APIs, which are designed to make Greasemonkey more powerful than HTML, according to Greaseblog, a blog devoted to the extension. As a result, scripts that rely on these APIs will fail with the 0.3.5 version. "Greasemonkey 0.3.5 is a 'neutered' version of Greasemonkey," said a developer in a post to the blog.
Still, according to the same post, people should only use 0.3.5 at this point.
"I strongly recommend that everyone either install Greasemonkey 0.3.5, or else disable or uninstall Greasemonkey completely," wrote the developer, who is currently working on a fix.
No reports of the flaw being exploited have surfaced, according to his post.
Several security flaws have been discovered in Firefox recently, and the Mozilla Foundation released a security update for the browser earlier this month.
Additionally, a promotional site for the Firefox browser was hacked last week. The attack on SpreadFirefox.com was an embarrassment to the Mozilla Foundation, which uses security as a main selling point for the browser.
one week 3 updates to mozilla firefox plus their marketing site gets hacked because they don't apply "UPDATES" all this with less than 10% market share
well, you can go shout "HOORAY! THANK GOD I USE IE!" right before ANOTHER critical update is released which was exploited on your computer at least 5X already. yeah, go on have your fun. the fox may have flaws but at least they get patched. and usually before they get exploited. MS WAIT for a hole to be exploited before they BEGIN making a patch.
Chamtech's spray-on antenna uses a nano material to provide a low-power boost to antenna range. The wireless-in-a-can product may some day bring an end to unsightly cell towers.
Whether Apple will release a new iPad next month doesn't seem to be the question as much as what day it will happen. A new rumor has it down to the day.
Tommy Jordan, the man who shot his daughter's laptop for YouTube, gets a visit from police and child protection services. Oh, and Good Morning America.
Along with green-lighting Google's buy of Motorola, the Justice Department today OKs an Apple-Microsoft-RIM partnership deal to buy Nortel patents, and Apple's plan to acquire Novell patents.
EnerG2 opens a plant to make an engineered carbon that will improve performance of energy storage devices and make storage for start-stop hybrid cars less expensive.
"Never Stop Playing" campaign for upcoming portable marks Sony's largest platform launch marketing spend, with ads to reach YouTube, Facebook, TV, and billboards in major cities.
As UC Berkeley students, the co-founders of "Back to the Roots" discovered they could grow mushrooms using recycled coffee grounds. Now their mushroom kit sells at grocery stores across the country.
Th Mozilla Foundation merely hosts the site that all these extensions can be s easily found on. Thy do not make nor release the extensions.
A flaw in an extension was found and fixed and the Mozilla team is serving a fixed version of that extension for their customers. As simple as that.
"making available"
plus their marketing site gets hacked because they don't apply "UPDATES"
all this with less than 10% market share
& we are suppose to belive FF is much secure
The avg user has never heard of GM....
Also, the marketing site breach had nothing to do with the security of the Firefox browser.