You are here

Sage RSS reader should be removed from Applications list

4 posts / 0 new
Last post
computerfreaker
computerfreaker's picture
Offline
Last seen: 13 years 8 months ago
Developer
Joined: 2009-08-11 11:24
Sage RSS reader should be removed from Applications list

Hi!

The Sage RSS reader is currently part of the Applications list. Unfortunately, Sage has a serious and well-known vulnerability that could allow a user's system to be remotely compromised. The vulnerability has existed for over a year, so IMHO the Sage author(s) have been given plenty of time to fix it; they have not, and addons.mozilla.org is taking action against Sage.
Because of the vuln, the seriousness of it, and the length of time it's remained unpatched, I think Sage should be removed from the list of applications.

Links:
http://www.vupen.com/english/advisories/2009/3324

http://forums.mozillazine.org/viewtopic.php?f=48&t=1603515

http://it.slashdot.org/story/09/11/20/1257232/Zero-Day-Vulnerabilities-I...

http://www.net-security.org/secworld.php?id=8527

OliverK
OliverK's picture
Offline
Last seen: 3 years 10 months ago
Developer
Joined: 2007-03-27 15:21
agreed. And, sage sucked

agreed. And, sage sucked anyway. Thunderbird and regular firefox work better.

Too many lonely hearts in the real world
Too many bridges you can burn
Too many tables you can't turn
Don't wanna live my life in the real world

gluxon
gluxon's picture
Offline
Last seen: 4 years 8 months ago
Developer
Joined: 2008-06-21 19:26
I don't think extentions

I don't think extentions should be in the list at all, we haven't modified them in any way.

Now, Eclipse Plugins are the new thing Blum

computerfreaker
computerfreaker's picture
Offline
Last seen: 13 years 8 months ago
Developer
Joined: 2009-08-11 11:24
Modification <> important, IMHO

I think addons should be in the list; modifications don't matter.
What PA.c is trying to do is provide people with good, portable tools. While addons can't be put into PortableApps format, they still can be #1 portable and #2 useful. That, IMHO, is enough to warrant admission into the Applications list.
An addon with a known, serious, long-unpatched vuln on the other hand...

"The question I would like to know, is the Ultimate Question of Life, the Universe and Everything. All we know about it is that the Answer is Forty-two, which is a little aggravating."

Log in or register to post comments