Homeppstream | pplive | emule | MP3 | Firefox |
The award-winning Web browser is now faster, more secure, and fully customizable to your online life. With Firefox 2, we’ve added powerful new features that make your online experience even better.
You position :Firefox >> Details Please remember website domain names www.firefox-uk.cn
Mozilla Foundation Security Advisory 2007-09 Small print : [big]
Mozilla Foundation Security Advisory 2007-09
Title: Privilege escalation by setting img.src to javascript: URI
Impact: Critical
Announced: March 5, 2007
Reporter: moz_bug_r_a4
Products: Firefox 1.5.0.9/2.0.0.1, SeaMonkey 1.0.7

Fixed in: Firefox 2.0.0.2
  Firefox 1.5.0.10
  SeaMonkey 1.1.1
  SeaMonkey 1.0.8

Description

moz_bug_r_a4 reports that the fix for MFSA 2006-72 in  Firefox 1.5.0.9 and Firefox 2.0.0.1 introduced a regression that allows scripts from web content to execute arbitrary code by setting the src attribute of an IMG tag to a specially crafted javascript: URI.

The same regression also caused javascript: URIs in IMG tags to be executed even if JavaScript execution was disabled in the global preferences. This facet was noted by moz_bug_r_a4 and reported independently by Anbo Motohiko.

Thunderbird is not affected by this flaw as it will not execute javascript: URIs in IMG tags.

Workaround

Upgrade to a version containing the fix. Disabling JavaScript does not protect against this flaw.
firefox录入:renwen@renwen.net    责任编辑:renwen@renwen.net 
  • 上一pianfirefox:

  • 下一pianfirefox:
  • [Comment] [collections] told friends joined clock article note
    The latest hot The latest recommendation Relatedfirefox
     Download Firefox® for free
     Firefox Open Source Articles
     Firefox Stats
     Extend Firefox 3 Contest
     Firefox to plug vulnerability …
     Firefox Update Plugs 8 Securit…
     New Firefox Add-On Makes Inter…
     Firefox Isn' Bloated, DRM …
     Firefox: An anti-Israeli consp…
     A Campaign to Block Firefox Us…
     Download Firefox® for free
     Mozilla shares scanning tool, …
     Firefox 3.0 beta coming soon
     Google Browser Sync extension …
     Firefox 3.0 Makes Leap Forward
     The award-winning Web browserM…
     Firefox web browser download1.…
    Firefox Stats
    Extend Firefox 3 Contest
    Firefox to plug vulnerabil…
    Firefox Update Plugs 8 Sec…
    New Firefox Add-On Makes I…
    Firefox Isn' Bloated, …
    Firefox: An anti-Israeli c…
    A Campaign to Block Firefo…
    Mozilla shares scanning to…
    Firefox 3 alpha 7 released
      Netizen : (only shows the latest 10. Comment on the contents represent users view, and has nothing to judge! )