Bug#560108: xulrunner: remote info disclosure via css

2010-04-10 Thread Delirium
forwarded 560108 https://bugzilla.mozilla.org/show_bug.cgi?id=14 thanks This is now fixed in upstream's trunk, but not in any releases yet. It looks like the fix will probably come out in Gecko 1.9.3 / Firefox 3.7. More info on the changes: http://blog.mozilla.com/security/2010/03/31/plugg

Bug#560108: xulrunner: remote info disclosure via css

2009-12-14 Thread Mike Hommey
severity 560108 important thanks On Tue, Dec 08, 2009 at 06:12:20PM -0500, Michael Gilbert wrote: > package: xulrunner > version: 1.9.0.13-0 > severity: serious > tags: security > > hi, > > it has been disclosed that it is possible for any website to query the > user's site viewing history via c

Bug#560108: xulrunner: remote info disclosure via css

2009-12-08 Thread Michael Gilbert
package: xulrunner version: 1.9.0.13-0 severity: serious tags: security hi, it has been disclosed that it is possible for any website to query the user's site viewing history via css. please see [0]. i have not personally checked whether this package is vulnerable, but it seems to be a general