Firelinking
Astro pointed me to an interessting Exploit for Firefox 1.0.2. On MacOS X the demonstration only works with User 501, since it tries to write into the root of the system partition, but it can be quite easily modified. Beside MacOS it has been successfully tested with FreeBSD, Linux and Windows.
That’s sad. Especially because the Firefox ppl advertised their browser as “the secure browser”.
Comment by Astro — Pungenday, 35th Discord, 3171. @ 79939
I have nearly 400 Packages installed on my FreeBSD box and I count only 6 advisories. But 5 of them are going to firefox :-/.
Comment by robo — Pungenday, 35th Discord, 3171. @ 80467