Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 68288 - Browser Vulnerabilities
Summary: Browser Vulnerabilities
Status: RESOLVED WONTFIX
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All All
: High normal (vote)
Assignee: Gentoo Security
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2004-10-20 09:56 UTC by Michiel de Bruijne
Modified: 2011-10-30 22:40 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Michiel de Bruijne 2004-10-20 09:56:41 UTC
http://secunia.com/multiple_browsers_dialog_box_spoofing_test/

affected browsers:
Konqueror
Mozilla / Mozilla Firefox
Opera
Netscape
Avant Browser
Maxthon
Safari


http://secunia.com/multiple_browsers_form_field_focus_test/

affected browsers:
Mozilla / Mozilla Firefox
Netscape
Avant Browser
Maxthon
Comment 1 solar (RETIRED) gentoo-dev 2004-10-20 10:03:28 UTC
This sounds like a dup of an older bug.
Comment 2 Thierry Carrez (RETIRED) gentoo-dev 2004-10-20 11:48:53 UTC
No, it's a new one...

In short, other tabs can open javascript dialogs whie you're looking at another tab, or watch keystrokes entered in their neighbour tabs.

Since you can't force your victim to open your malicious site next to your super-secret banking site, you have to wait for them to do this...

Not really exploitable... by itself.
Comment 3 Kurt Lieber (RETIRED) gentoo-dev 2004-10-22 08:25:55 UTC
seems low-risk to me.  
Comment 4 Kurt Lieber (RETIRED) gentoo-dev 2004-10-22 08:26:35 UTC
closing this as wontfix.