Closed Bug 427906 Opened 18 years ago Closed 17 years ago

ChatZilla activates chrome and javascript URLs in channels

Categories

(Other Applications Graveyard :: ChatZilla, defect)

defect
Not set
normal

Tracking

(Not tracked)

RESOLVED INCOMPLETE

People

(Reporter: bc, Assigned: rginda)

Details

(Whiteboard: [sg:low])

steps to reproduce: 1. paste javascript:alert%281%29 into a channel 2. click on the linkified link actual results: alert(1) is executed by firefox. expected results: ? 1. paste chrome://browser/content into a channel 2. click on the linkified link actual results: browser chrome is loaded into firefox tab expected results: ?
Whiteboard: [sg:low]
I'm really not sure this is a problem, but perhaps that makes me naive. I'd be willing to unlink the javascript bits, but I'm not sure if we should block chrome URLs. Anyway, relevant code is here: http://mxr.mozilla.org/seamonkey/source/extensions/irc/xul/content/mungers.js#166 We can probably hardcode chrome: and javascript: to not work if necessary. Anyone feel like doing a patch?
I forgot, nobody can see this bug. Let's fix that...
It would be nice if people could file bugs that actually indicate what the damn problem is supposed to be. The URLs are thrown over to Firefox using standard methods (openTopWin and openNewWindowWith), which ought not be insecure themselves. If the browser wants to block javascript/chrome URLs, those functions or something they call is what you want to 'fix'.
Hardware: PC → All
Summary: Chatzilla activates chrome and javascript urls in channels → ChatZilla activates chrome and javascript URLs in channels
Sorry for not living up to your expectations. I won't make the mistake of filing a bug on chatzilla again. You are such a fine example and inspiration for all of us. Please keep of the good work of alienating everyone you work with.
Status: NEW → RESOLVED
Closed: 17 years ago
Resolution: --- → INVALID
Is it really too much to ask that people filing security-sensitive bugs actually say what the security problem is? Surely not...
Resolution: INVALID → INCOMPLETE
Group: security
Product: Other Applications → Other Applications Graveyard
You need to log in before you can comment on or make changes to this bug.