Bug#579136: CSS visited elements allow for disclosure of users browser history

2012-01-16 Thread Michael Gilbert
severity 579136 serious thanks Hi, I've just tested this, and that site now causes a segfault. So, it may be a fix was attempted at this, but not done quite right? Anyway, a remotely triggerable segfault is rather not good, so I'm raising the severity. -- To UNSUBSCRIBE, email to debian-bugs-

Bug#579136: CSS visited elements allow for disclosure of users browser history

2010-04-25 Thread markhobley
Package: midori Version: 0.2.2-1 Severity: normal There is a "Disclosure of user information" security flaw in the midori browser due to the implementation of support for CSS :visited pseudoclass elements. It is possible to specify a background-url attribute which will make a request to the serv