Ian Hickson schrieb:
On Fri, 9 Jun 2006, Julian Reschke wrote:
Speaking of which, if this is a security problem: why hasn't it been
fixed in Firefox 1.5 and/or IE 6SP2? Both seem to happily send CONNECT
requests when asked for.
It was fixed in IE7. I would presume that the other browser vendors are
still weighing their options, and that that is probably why the working
group is still discussing this (given that most members of the working
group are browser vendors).
IE7 is an unreleased product.
IE6 is what's supported by Microsoft and which is in active maintenance.
If there's a security risk in the current implementation, I would expect
Microsoft to fix it there. Of course the same applies to FF.
Best regards, Julian