Red Hat Bugzilla – Bug 151714
CAN-2005-0401 Drag and drop loading of privileged XUL
Last modified: 2007-11-30 17:07:17 EST
A malicious page that could lure a user into dragging something (such
as a fake scrollbar) can bypass the restriction on opening privileged
XUL. The startup scripts in the XUL will run with enhanced privilege,
though the actions taken upon merely opening most XUL are benign. So
far no way to run arbitrary code supplied by the attacker has been
found, but this could be a stepping-stone to future attacks.
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on the solution and/or where to find the updated files,
please follow the link below. You may reopen this bug report
if the solution does not work for you.