[tor-bugs] #12430 [Tor Browser]: Disable the jar: protocol for external resources via preference

Tor Bug Tracker & Wiki blackhole at torproject.org
Wed Feb 11 23:02:44 UTC 2015


#12430: Disable the jar: protocol for external resources via preference
-------------------------+-------------------------------------------------
     Reporter:  gk       |      Owner:  tbb-team
         Type:           |     Status:  closed
  enhancement            |  Milestone:
     Priority:  normal   |    Version:
    Component:  Tor      |   Keywords:  tbb-security, tbb-firefox-patch,
  Browser                |  tbb-isec-report, TorBrowserTeam201502R,
   Resolution:  fixed    |  MikePerry201502R
Actual Points:           |  Parent ID:  #9387
       Points:           |
-------------------------+-------------------------------------------------
Changes (by mikeperry):

 * status:  needs_review => closed
 * resolution:   => fixed


Comment:

 I had a chance to take a closer look at the iSEC patch with context, and
 it seemed to me that we should be blocking remote JAR loads before the
 load starts. I added a fixup commit to check the pref earlier (in
 nsJARChannel::AsyncOpen()) and pushed this for 4.5-alpha-4.

 Just in case there was an additional codepath to
 nsJARChannel::OnDownloadComplete() other than nsJARChannel::AsyncOpen(), I
 left the original iSEC check in too.

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/12430#comment:10>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list