LastPass RCE vulnerability fixed
bugs.chromium.org
LastPass RCE vulnerability fixed
1–10 of 188 posts
Re: LastPass RCE vulnerability fixed
#2Re: LastPass RCE vulnerability fixed
#3Re: LastPass RCE vulnerability fixed
#4Looks like this was discovered by the same guy that discovered CloudFail. That dude is amazing.
Re: LastPass RCE vulnerability fixed
#5Looks like this was discovered by the same guy that discovered CloudFail. That dude is amazing.
Re: LastPass RCE vulnerability fixed
#6Re: LastPass RCE vulnerability fixed
#7Apparently this was fixed server-side and does not require any update to the client. However the default version on addons.mozilla.org is very old for some reason, so if you are running 3.x it wouldn't hurt to download the latest. You can get it either from LastPass's website directly or from https://addons.mozilla.org/en-US/firefox/addon/lastpass-pass...
See https://blog.lastpass.com/2017/03/plans-to-retire-the-lastpa... for details.
Re: LastPass RCE vulnerability fixed
#8> (Please note, issue 1188 which affects LastPass on firefox is not fixed, and still works)
Re: LastPass RCE vulnerability fixed
#9I've got to say, this attack looks a little too obvious; that doesn't reflect well on lastpass.
Re: LastPass RCE vulnerability fixed
#10Looks like this was discovered by the same guy that discovered CloudFail. That dude is amazing.
https://bugs.chromium.org/p/project-zero/issues/list?can=1&q...