This bug is a placeholder for the Suite version of bug 268370, the only known instance of bug 267645 (leaking install directory via component exceptions). The Suite version of the Secunia advisory is http://secunia.com/advisories/20256/ The patch in attachment 224811 [details] [diff] [review] looks like it would apply to the xpfe/components/sidebar/src/nsSidebar.js copy without change.
Presuming this should block the next SeaMonkey release
Created attachment 226396 [details] [diff] [review] merged firefox patch from bug 268370 Carrying over reviews and approval from Firefox equivalent bug, requesting approval for the SeaMonkey-only version. I assume you guys might prefer this simple version on the 1.8 branch and trunk rather than Gavin's full "localize sidebar" patch from bug 338989 (which might not match the SeaMonkey sidebar), but if you want that instead--and have someone to do it--go ahead and deny approval for seamonkey1.1
Comment on attachment 226396 [details] [diff] [review] merged firefox patch from bug 268370 first a=me for 1.0.3
Comment on attachment 226396 [details] [diff] [review] merged firefox patch from bug 268370 We sure want this version on 1.8.0 branch, need to discuss about 1.8 and trunk with other devs though...
Fix checked in to the 1.8.0 branch
Comment on attachment 226396 [details] [diff] [review] merged firefox patch from bug 268370 a=me for 1.1a
Has this landed anywhere else then 1.8.0 branch? If not, it probably should land on both trunk and 1.8 branch, so that the problem is fixed, we can always go and port a better solution later, if wanted/needed, right?
This didn't land anywhere else pending some kind of decision on the 1.8/trunk fix and the fact that my default queries weren't looking for seamonkey-approved patches (sorry about that). I agree it's probably better to go ahead and land this rather than wait for something better to come along.
Dan, it's your patch, so could you please go ahead and check it in on both trunk and 1.1 branch? We really want to have this fixed in upcoming releases.
Fixed on 1.8 branch and trunk