iTnews

Lastpass patches creds-stealing bugs in browser plugins

By Juha Saarinen on Mar 23, 2017 6:47AM
Lastpass patches creds-stealing bugs in browser plugins

Google security researcher finds three in a row.

Popular password manager Lastpass has plugged bugs in its browser extensions for Google Chrome and Mozilla Firefox that allow attackers to steal passwords and execute arbitrary code.

The vulnerabilities were discovered by Google's Project X security researcher Tavis Ormandy, who reported them to Lastpass.

He originally discovered a remote code execution and password stealing flaw in the version 4.1.42 browser extension for Chrome and Firefox and reported it to Lastpass, with a proof of concept exploit that comprised two lines of Javascript.

The flaw requires the Lastpass binary component plugin, which is installed by default for the Lastpass browser extensions in Microsoft's Internet Explorer and Mozilla Firefox, but not in Google Chrome.

Lastpass patched that vulnerability, but soon after, Ormandy reported that he had found two further bugs.

One that allows password stealing was reported in 2015, and received an incomplete fix. Ormandy said exploiting that bug was "not trivial because of the weird context".

A second extension bug could be exploited to open non-websafe browser links, and allow malicious sites to read user credentials silently. 

The flaws were fixed in less than 24 hours, and Ormandy commended Lastpass for being quick to act. The company said there was no indication that the vulnerabilties are being exploited in the wild.

Users are advised to upgrade their browser extensions to Firefox: 4.1.36a, Chrome: 4.1.42.82, Edge: 4.1.30, and Opera: 4.1.28, Lastpass said.

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © iTnews.com.au . All rights reserved.
Tags:
chrome google lastpass security tavis ormandy

Partner Content

As Australian companies lean more heavily on the cloud, edge security is finding its stride
Partner Content As Australian companies lean more heavily on the cloud, edge security is finding its stride
Tackling cybersecurity in 2021
Partner Content Tackling cybersecurity in 2021
Why companies fail at picking cloud modernisation partners
Promoted Content Why companies fail at picking cloud modernisation partners
Apathetic leadership remains cybersecurity barrier in Australia
Promoted Content Apathetic leadership remains cybersecurity barrier in Australia

Sponsored Whitepapers

Is the technology refresh dead?
Is the technology refresh dead?
DevSecOps: A framework for digital innovation
DevSecOps: A framework for digital innovation
Encryption: Protect your most critical data
Encryption: Protect your most critical data
Overcoming data security challenges in a hybrid, multicloud world
Overcoming data security challenges in a hybrid, multicloud world
Move beyond passwords
Move beyond passwords

Events

  • On-Demand Webinar: How Poly and Microsoft are Embracing Future Work Environments
  • [Webinar] - Transformation versus compliance – a guide for CXOs
  • Masters of Microsoft Licensing
By Juha Saarinen
Mar 23 2017
6:47AM
0 Comments

Related Articles

  • Google draws US antitrust scrutiny over third-party cookies ban
  • Lazarus Group behind security researcher attacks
  • Update Chrome or risk remote takeover, US govt warns
  • Google patches exploited Chrome zero-day
Share on Twitter Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Aussie Broadband to white label its services

Aussie Broadband to white label its services

Aussie Broadband says some customers are switching providers to get high-speed NBN discounts

Aussie Broadband says some customers are switching providers to get high-speed NBN discounts

Vodafone hit by nationwide 4G outage

Vodafone hit by nationwide 4G outage

ATO loses its cyber security chief

ATO loses its cyber security chief

You must be a registered member of iTnews to post a comment.
Log In | Register
All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of nextmedia's Privacy Policy and Terms & Conditions.