Firefox, Thunderbird, Mozilla Suite Upgrades Released
Wednesday August 4th, 2004
mozilla.org today released minor upgrades to three of its major products. Firefox 0.9.3, Thunderbird 0.7.3 and Mozilla 1.7.2 are all now available. These three new releases were created to correct 4 possible security vulnerabilities in past versions of each product. The Buildbar has links for all three releases.
#62 Re: Re: XUL Vulnerability
Thursday August 5th, 2004 4:24 AM
You are replying to this message
Indeed. So the way to "fix" it will be to make it harder for sites to spoof the UI, but ensuring that some real UI exists on all windows. XUL spoofing is something of a red herring - the solution needs to cover (D)HTML spoofs too (and the problem exists in other browsers).