Comment 12 for bug 16231

Revision history for this message
Peter Weissgerber (usenet-p-weissgerber) wrote :

Please bear in mind that Firefox release 1.0.3 did not close this favicons code
execution bug completetly. For example, the "c't Browser demo" at
http://www.heise.de/security/dienste/browsercheck/demos/nc/mozdemo3.shtml still
works with Firefox 1.0.3 as well as with the latest Ubuntu Firefox package
("c't" is a major computer magazine in Germany. Just click at "Test ausführen".
Then, a xterm will open that shows all files on your hard drive). This bug is
fixed in Firefox 1.0.4. Please include these fixes in the next Hoary security
release.