[tbb-bugs] #20442 [Applications/Tor Browser]: Backport fix for CVE-2016-5279: local path disclosure after drag and drop (bug 1249522)

Tor Bug Tracker & Wiki blackhole at torproject.org
Mon Oct 24 07:13:43 UTC 2016


#20442: Backport fix for CVE-2016-5279: local path disclosure after drag and drop
(bug 1249522)
-------------------------------------+-------------------------------------
     Reporter:  gk                   |      Owner:  tbb-team
         Type:  task                 |     Status:  new
     Priority:  High                 |  Milestone:
    Component:  Applications/Tor     |    Version:
  Browser                            |   Keywords:  TorBrowserTeam201610,
     Severity:  Major                |  GeorgKoppen201610
Actual Points:                       |  Parent ID:
       Points:                       |   Reviewer:
      Sponsor:                       |
-------------------------------------+-------------------------------------
 The fix for CVE-2016-5279 got not backported to ESR45, probably as it did
 not seem critical enough to Mozilla. I think a fix might fit into Tor
 Browser pretty well, though (thanks to nicoo for pointing to this bug).

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/20442>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tbb-bugs mailing list