Closed Bug 721408 Opened 10 years ago Closed 10 years ago

moz-page-thumb protocol should not access from a web page

Categories

(Toolkit :: Places, defect)

12 Branch
defect
Not set
normal

Tracking

()

RESOLVED DUPLICATE of bug 721398
Tracking Status
firefox11 --- unaffected
firefox12 - affected

People

(Reporter: teramako, Unassigned)

References

Details

(Keywords: privacy)

Attachments

(1 file)

Attached file thumbnail.html
User Agent: Mozilla/5.0 (Windows NT 5.1; rv:12.0a1) Gecko/20120126 Firefox/12.0a1
Build ID: 20120126031113

Steps to reproduce:

 moz-page-thumb://thumbnail?url=.... can access from a web page. It should access only in privileged site for security and privacy reason.
If can access on a web page, evil site owner can know that the user accessed or not the URL in past.
Blocks: 497543
Component: Untriaged → Places
Keywords: privacy
OS: Windows XP → All
Product: Firefox → Toolkit
QA Contact: untriaged → places
Hardware: x86 → All
Assignee: nobody → ttaubert
Status: UNCONFIRMED → RESOLVED
Closed: 10 years ago
Resolution: --- → DUPLICATE
Duplicate of bug: CVE-2012-0476
Assignee: ttaubert → nobody
You need to log in before you can comment on or make changes to this bug.