Mozilla Foundation Security Advisory 2009-31

XUL scripts bypass content-policy checks

Announced
June 11, 2009
Reporter
Wladimir Palant
Impact
Low
Products
Firefox
Fixed in
  • Firefox 3.0.11

Description

Mozilla add-on developer and community member Wladimir Palant reported that content-loading policies were not checked before loading external script files into XUL documents. The severity of this problem would depend on the reasons behind the content policy check, which include privacy from "web bugs" in Thunderbird mail messages, blocking of Ads and Ad-server tracking in AdBlock Plus.

The original version of this advisory incorrectly claimed that NoScript protection could by bypassed; NoScript was unaffected.

References