61db Ryan Shaw » 2005 » July » 19

7/19/2005

Severe Security Flaw Found in Greasemonkey

Filed under: intermediation, security — ryan @ 9:10 am

According to Greaseblog:

The flaw allows any website which matches at least one user script (even * scripts) to read any local file on your machine, or to list the contents of local directories. The flaw applies to Greasemonkey on all platforms.

If you’re using Greasemonkey, immediately uninstall or disable it, or update to version 0.3.5 (which will break any userscript that relies on XML over HTTP requests, like amazon2melvyl).

Powered by WordPress

0