Your message dated Sat, 26 Jul 2008 20:53:28 +0200
with message-id <[EMAIL PROTECTED]>
and subject line Appears to be fixed in Iceweasel 3
has caused the Debian Bug report #382001,
regarding Location bar can be spoofed
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [EMAIL PROTECTED]
immediately.)


-- 
382001: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=382001
Debian Bug Tracking System
Contact [EMAIL PROTECTED] with problems
--- Begin Message ---
Package: firefox
Version: 1.5.dfsg+1.5.0.6-1
Severity: important
Tags: security

The location bar can be spoofed, which means that the "yellow URL
input field on TLS" security feature is useless.  To reproduce this,
visit http://www.national.com.au/ and click on first "Login" link at
the upper right (under the "Internet Banking" caption).  A new browser
window opens, but it lacks the location bar.  This means that it can
be mimicked using JavaScript.

This behavior can be cchanged in the Firefox registry (via
dom.disable_window_open_feature.location and perhaps others as well),
but the default ist definitely wrong.

-- 
Florian Weimer                <[EMAIL PROTECTED]>
BFK edv-consulting GmbH       http://www.bfk.de/
Durlacher Allee 47            tel: +49-721-96201-1
D-76131 Karlsruhe             fax: +49-721-96201-99


--- End Message ---
--- Begin Message ---
Version: 3.0.1-1

dom.disable_window_open_feature.location defaults to true in
Iceweasel 3, apparently.


--- End Message ---

Reply via email to