|
|
|
![]() |
Vulnerability Note VU#319464The Wizz RSS Reader chrome access vulnerabilityOverviewThe Wizz RSS Reader contains a vulnerability that may allow an attacker to take any action that Mozlla Firefox can.I. DescriptionThe Mozilla Firefox user interface components outside of the content area are created using chrome. This includes toolbars, menu bars, progress bars, and window title bars. Chrome provides content, locale, and skin information for the user interface. The Wizz RSS reader is an extension to Mozilla Firefox that searches and displays RSS feeds.The Wizz RSS Reader reader contains a vulnerability. This vulnerability occurs because The Wizz allows javascript in an RSS feed's DOM to be executed in the context of the Wizz RSS Reader's chrome window. Version 2.1.9 of the Wizz RSS reader has been released to address this vulnerability. Users are encouraged to update to version 2.1.9 as soon as possible.
References
Thanks to the N-CIRT Lab for reporting this vulnerability. This document was written by Ryan Giobbi.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
|||||||||||||||||||||||||||||||||||||
|
|||||||||||||||||||||||||||||||||||||||