Opening this task to catch dupes. Can mark invalid when fixed.
** Also affects: firefox-3.5 (Ubuntu)
Importance: Undecided
Status: New
** Changed in: firefox-3.5 (Ubuntu)
Importance: Undecided = High
** Changed in: firefox-3.5 (Ubuntu)
Status: New = Triaged
--
Firefox 3.5
Micah Gersten: I respect your judgement concerning whether this is a security
bug or not, however I can see several ways an attacker can exploit this:
1. Using a MITM attack and on the fly replace the deb-file to be downloaded
from adobe.com with a specially prepaid package as laid out here:
Small note - it appears that on the initial popup window containing the
text Press next to install these plugins that there should be a list
of plugins to install (if my memory of older versions serves me
correctly). Not only is the list blank, but there is no list widget.
--
Firefox 3.5 Plugin
Thanks for taking the time to report this bug and helping to make Ubuntu
better. We appreciate the difficulties you are facing, but this appears
to be a regular (non-security) bug. I have unmarked it as a security
issue since this bug does not show evidence of allowing attackers to
cross privilege
Moving to Ubufox.
Thanks for reporting this bug and any supporting documentation. Since this bug
has enough information provided for a developer to begin work, I'm going to
mark it as Triaged and let them handle it from here. Thanks for taking the time
to make Ubuntu better!
** Package
** Changed in: firefox-3.5 (Ubuntu)
Status: New = Confirmed
--
Firefox 3.5 Plugin Finder Service in Ubuntu Karmic 9.10 displays No suitable
plugins were found for flash
https://bugs.launchpad.net/bugs/440987
You received this bug notification because you are a member of Ubuntu
Bugs,
** Attachment added: Dependencies.txt
http://launchpadlibrarian.net/32886050/Dependencies.txt
** Visibility changed to: Public
--
Firefox 3.5 Plugin Finder Service in Ubuntu Karmic 9.10 displays No suitable
plugins were found for flash
https://bugs.launchpad.net/bugs/440987
You received