Mozilla Foundation Security Advisory 2009-31
XUL scripts bypass content-policy checks
- Announced
- June 11, 2009
- Reporter
- Wladimir Palant
- Impact
- Low
- Products
- Firefox
- Fixed in
-
- Firefox 3.0.11
Description
Mozilla add-on developer and community member Wladimir Palant reported that content-loading policies were not checked before loading external script files into XUL documents. The severity of this problem would depend on the reasons behind the content policy check, which include privacy from "web bugs" in Thunderbird mail messages, blocking of Ads and Ad-server tracking in AdBlock Plus.
The original version of this advisory incorrectly claimed that NoScript protection could by bypassed; NoScript was unaffected.