Tooltips originating from a tab page are shown in other tab pages

NEW
Unassigned

Status

()

Core
General
6 years ago
5 years ago

People

(Reporter: EZ, Unassigned)

Tracking

({sec-low})

11 Branch
x86_64
Windows Vista
sec-low
Points:
---

Firefox Tracking Flags

(Not tracked)

Details

(Whiteboard: DUPE?)

Attachments

(1 attachment)

(Reporter)

Description

6 years ago
Created attachment 612508 [details]
FireFox_Tooltip_Bug.jpg

User Agent: Mozilla/5.0 (Windows NT 6.0; WOW64; rv:11.0) Gecko/20100101 Firefox/11.0
Build ID: 20120312181643

Steps to reproduce:

I have a couple of tab pages open. One with the TFS (Microsoft Team Foundation) web access and one with Google Analytics and some others. When I hover over one of the graphs in the Google Analytics, I get tooltips that originate from the TFS web access page.


Actual results:

When I hover over one of the graphs in the Google Analytics, I get tooltips that originate from the TFS web access page. 
I verified that the last tooltip shown in the TFS web access page is also shown as the text in the Google Analytics page.


Expected results:

It should never happen that whatever content from a tab page is shown in another tab page in whatever way. This to me sounds like a security issue. The tooltips shown in the Google Analytics page should only contain text that applies to the content of Google Analytics page and not content of other tab pages.
Status: UNCONFIRMED → RESOLVED
Last Resolved: 6 years ago
Resolution: --- → DUPLICATE
Whiteboard: [sg:dupe 575294]
Duplicate of bug: 575294
EZ, there are builds available with fixes for bug 575294 here:
https://ftp.mozilla.org/pub/mozilla.org/firefox/try-builds/mpalmgren@mozilla.com-748972c39205/

Please let me know if that fixes the issue you reported, thanks!

(note that the builds are based on Fx14 so you might want to create a temporary
profile for testing, see http://support.mozilla.org/en-US/kb/Managing-profiles)
Let's reopen this bug until we can get confirmation from the reporter
that this is actually the same issue as bug 575294.  My guess it's not.
Status: RESOLVED → UNCONFIRMED
Resolution: DUPLICATE → ---
Whiteboard: [sg:dupe 575294]
OK, if it's not bug 575294 then it's some other one -- we've had this problem for years.
Group: core-security
Status: UNCONFIRMED → NEW
Ever confirmed: true
Whiteboard: [sg:low spoof] DUPE?
Keywords: sec-low
Blocks: 753035
Component: Untriaged → General
Product: Firefox → Core
Whiteboard: [sg:low spoof] DUPE? → DUPE?
You need to log in before you can comment on or make changes to this bug.