|
||
![]() |
||
![]() |
You position :Firefox >> Details | Please remember website domain names www.firefox-uk.cn |
|
|||||
| Mozilla Foundation Security Advisory 2007-09 | |||||
|
Impact: Critical Announced: March 5, 2007 Reporter: moz_bug_r_a4 Products: Firefox 1.5.0.9/2.0.0.1, SeaMonkey 1.0.7 Fixed in: Firefox 2.0.0.2 Firefox 1.5.0.10 SeaMonkey 1.1.1 SeaMonkey 1.0.8 Descriptionmoz_bug_r_a4 reports that the fix for MFSA 2006-72 in Firefox 1.5.0.9 and Firefox 2.0.0.1 introduced a regression that allows scripts from web content to execute arbitrary code by setting thesrc attribute of an IMG tag to a specially crafted javascript: URI.
The same regression also caused javascript: URIs in Thunderbird is not affected by this flaw as it will not execute javascript: URIs in WorkaroundUpgrade to a version containing the fix. Disabling JavaScript does not protect against this flaw. |
|||||
| firefox录入:renwen@renwen.net 责任编辑:renwen@renwen.net | |||||
|
[Comment] [collections] told friends joined clock
article note
|
|||||
Netizen
: (only shows the latest 10. Comment on the contents represent users
view, and has nothing to judge! ) |
| | As the front page | hosting | Domain Name Registration | |
|
|