Closed Bug 495967 Opened 15 years ago Closed 15 years ago

Unfair software vendors (like Microsoft) could silently install extensions without user permission

Categories

(Firefox :: Security, enhancement)

All
Windows XP
enhancement
Not set
normal

Tracking

()

RESOLVED DUPLICATE of bug 476430

People

(Reporter: radist-hack, Unassigned)

Details

User-Agent:       Mozilla/5.0 (Windows; U; Windows NT 5.1; ru; rv:1.9.0.10) Gecko/2009042316 Firefox/3.0.10
Build Identifier: Mozilla/5.0 (Windows; U; Windows NT 5.1; ru; rv:1.9.0.10) Gecko/2009042316 Firefox/3.0.10

Microsoft .NET Framework 3.5 Service Pack 1 silently installed "Microsoft .NET Framework Assistant" extension via registry. Generally, it's not a good practice and also it's a large security hole.
Of course, such way could be useful for administrative installation but a some way of moderating such silent installations should be proposed to end-users who doesn't need such installations.

Reproducible: Always

Steps to Reproduce:
1. Install Firefox, run it once (to create profile) and close.

2.a. Install "Microsoft .NET Framework 3.5 Service Pack 1"
<<< or alternatively >>>
2.b.1. Download *.xpi file for any firefox extension (which could be installed normally) and extract it content into any folder, remember the path where it was installed.
2.b.2. Open registry editor, navigate to HKLM\Software\Mozilla\Firefox\Extensions (create if it doesn't exists) and create the string parameter "your extension name" with value "full\path\to\folder\where\xpi\was\extracted".

3. Run Firefox and open extensions list
Actual Results:  
"Microsoft .NET Framework Assistant" is installed and could not be simply uninstalled.

Expected Results:  
Request for installing "Microsoft .NET Framework Assistant" (at least for those who has write access to HKLM\Software\Mozilla\Firefox\Extensions).
This is a duplicate of bug 476430 I think.
oops, sorry
Status: UNCONFIRMED → RESOLVED
Closed: 15 years ago
Resolution: --- → DUPLICATE
You need to log in before you can comment on or make changes to this bug.