[tor-bugs] #15599 [Applications/Tor Browser]: Range requests used by pdfjs are not isolated to URL bar domain

Tor Bug Tracker & Wiki blackhole at torproject.org
Fri Jan 19 03:28:46 UTC 2018


#15599: Range requests used by pdfjs are not isolated to URL bar domain
-------------------------------------------------+-------------------------
 Reporter:  gk                                   |          Owner:
                                                 |  pospeselr
     Type:  defect                               |         Status:
                                                 |  needs_review
 Priority:  High                                 |      Milestone:
Component:  Applications/Tor Browser             |        Version:
 Severity:  Normal                               |     Resolution:
 Keywords:  tbb-linkability,                     |  Actual Points:
  TorBrowserTeam201801R                          |
Parent ID:                                       |         Points:
 Reviewer:                                       |        Sponsor:
-------------------------------------------------+-------------------------
Changes (by pospeselr):

 * status:  assigned => needs_review
 * keywords:  tbb-linkability, TorBrowserTeam201801 => tbb-linkability,
     TorBrowserTeam201801R


Comment:

 Patch to disable range-based requests in pdf.js.  Fixes the domain
 isolation issue, at the expense of usability.  With this pref flipped, the
 entire pdf must be downloaded before being viewed and interacted with.

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/15599#comment:12>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list