Comment #2 on issue 19403 by [email protected]: Need tests for an  
extension update being improperly signed
http://code.google.com/p/chromium/issues/detail?id=19403

A somewhat related test we should also add is for the case of an update  
manifest
mentioning updated extensions we didn't expect (eg extensions A and B, with  
different
update_url's, are both installed, and the manifest for A includes a  
download link for a
new version of B). Assuming we're doing the public key check right, I think  
the risk in
this case is a denial-of-service type attack, by listing a large number of
unexpected/bogus extensions in a manifest.



--
You received this message because you are listed in the owner
or CC fields of this issue, or because you starred this issue.
You may adjust your issue notification preferences at:
http://code.google.com/hosting/settings

--~--~---------~--~----~------------~-------~--~----~
Automated mail from issue updates at http://crbug.com/
Subscription options: http://groups.google.com/group/chromium-bugs
-~----------~----~----~----~------~----~------~--~---

Reply via email to