Common Vulnerabilities and Exposures assigned an identifier CVE-2009-4130 to the following vulnerability: Name: CVE-2009-4130 URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4130 Assigned: 20091201 Reference: BUGTRAQ:20091205 Mozilla Firefox JavaScript Prompt Spoofing Weakness Reference: URL: http://archives.neohapsis.com/archives/bugtraq/2009-12/0104.html Reference: BID:37232 Reference: URL: http://www.securityfocus.com/bid/37232 Reference: SECTRACK:1023287 Reference: URL: http://securitytracker.com/id?1023287 Reference: XF:firefox-makescriptdialogtitle-spoofing(54612) Reference: URL: http://xforce.iss.net/xforce/xfdb/54612 Visual truncation vulnerability in the MakeScriptDialogTitle function in nsGlobalWindow.cpp in Mozilla Firefox allows remote attackers to spoof the origin domain name of a script via a long name.
This is https://bugzilla.mozilla.org/show_bug.cgi?id=531613
Upstream closed this as CLOSED:WORKSFORME implying this is not a bug.