Bugzilla – Bug 862348
VUL-0: CVE-2014-1479: Firefox/Thunderbird/Seamonkey: Clone protected content with XBL scopes
Last modified: 2014-02-10 10:44:16 UTC
CVE-2014-1479 Security researcher Cody Crews reported a method to bypass System Only Wrappers (SOW) by using XML Binding Language (XBL) content scopes to clone protected XUL elements. This could be used to clone anonymous nodes, making trusted XUL content web accessible. References: http://www.mozilla.org/security/announce/2014/mfsa2014-02.html http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-1479 https://bugzilla.redhat.com/show_bug.cgi?id=1060940
bugbot adjusting priority
problem is covered with new Firefox version *** This bug has been marked as a duplicate of bug 861847 ***