MozillaZine

Firefox, Thunderbird, Mozilla Suite Upgrades Released

Wednesday August 4th, 2004

mozilla.org today released minor upgrades to three of its major products. Firefox 0.9.3, Thunderbird 0.7.3 and Mozilla 1.7.2 are all now available. These three new releases were created to correct 4 possible security vulnerabilities in past versions of each product. The Buildbar has links for all three releases.


#62 Re: Re: XUL Vulnerability

by mlefevre

Thursday August 5th, 2004 4:24 AM

You are replying to this message

Indeed. So the way to "fix" it will be to make it harder for sites to spoof the UI, but ensuring that some real UI exists on all windows. XUL spoofing is something of a red herring - the solution needs to cover (D)HTML spoofs too (and the problem exists in other browsers).