[tbb-bugs] #30304 [Applications/Tor Browser]: Browser locale can be obtained via DTD strings

Tor Bug Tracker & Wiki blackhole at torproject.org
Fri Apr 26 10:16:47 UTC 2019

#30304: Browser locale can be obtained via DTD strings
 Reporter:  acat    |          Owner:  tbb-team
     Type:  defect  |         Status:  new
 Priority:  High    |      Component:  Applications/Tor Browser
  Version:          |       Severity:  Normal
 Keywords:          |  Actual Points:
Parent ID:          |         Points:
 Reviewer:          |        Sponsor:
 See https://bugzilla.mozilla.org/show_bug.cgi?id=467035.

 Works in Tor Browser and Firefox 67 (with a different dtd file as in the
 bugzilla PoC), probably also next ESR.

 Did not do a PoC but it would be easy to get a specific string in all
 locales, and just compare with value obtained via a hidden iframe that
 loads an xml with the translated string.

Ticket URL: <https://trac.torproject.org/projects/tor/ticket/30304>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online

More information about the tbb-bugs mailing list