Red Hat Bugzilla – Bug 142390
CAN-2004-1156 Frame injection vulnerability.
Last modified: 2007-11-30 17:07:05 EST
Secunia reported a pair of frame injection vulnerabilities that could result in popup blocking. http://secunia.com/secunia_research/2004-13/advisory/ https://bugzilla.mozilla.org/show_bug.cgi?id=273699 This issue also affects RHEL2.1
This issue also affects galeon, I'm not sure if it would be becuase galeon uses the mozilla backend, or if it's an issue in the browser interface. If a new bug is needed for galeon, please let me know and I'll file it.
The secunia demo no longer works. I've created a demo located here http://people.redhat.com/bressers/spoof_test/
An advisory has been issued which should help the problem described in this bug report. This report is therefore being closed with a resolution of ERRATA. For more information on the solution and/or where to find the updated files, please follow the link below. You may reopen this bug report if the solution does not work for you. http://rhn.redhat.com/errata/RHSA-2005-384.html