thunderbird "show remote content" and "other actions" buttons dangerously close

Bug #945491 reported by B Bobo
8
This bug affects 1 person
Affects Status Importance Assigned to Milestone
thunderbird (Ubuntu)
Expired
Undecided
Unassigned

Bug Description

The "show remote content" button is immediately underneath the "other actions" button. They are much too close. It's too easy to hit "show remote content" by mistake when you try to select "other actions".

The consequence is that untrusted dangerous remote content can be loaded.

thunderbird-3 to thunderbird-17.0

B Bobo (yout-bobo123)
tags: added: accessibility
B Bobo (yout-bobo123)
tags: added: security
B Bobo (yout-bobo123)
summary: - thunderbird "show remote content" and "other actions" buttons too close
+ thunderbird "show remote content" and "other actions" buttons
+ dangerously close
information type: Public → Public Security
description: updated
description: updated
Revision history for this message
Marc Deslauriers (mdeslaur) wrote : Bug is not a security issue

Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privilege boundaries nor directly cause loss of data/privacy. Please feel free to report any other bugs you may find.

information type: Public Security → Public
Revision history for this message
gf (gf-interlinks-deactivatedaccount) wrote :

Hello B. Bobo.,
Thank you for submitting this bug and reporting a problem with Thunderbird.

You made this bug report in 2012 and there have been several versions of Ubuntu and Thunderbird since then.

Could you confirm that this is no longer a problem and that we can close the ticket?
Or, if it is still a problem, could you run the following (only once):
apport-collect BUGNUMBER

and upload the updated logs and and any other logs that are relevant for this particular issue.

Thank you again for helping make Ubuntu and Thunderbird better.

G

Changed in thunderbird (Ubuntu):
status: New → Incomplete
Revision history for this message
Launchpad Janitor (janitor) wrote :

[Expired for thunderbird (Ubuntu) because there has been no activity for 60 days.]

Changed in thunderbird (Ubuntu):
status: Incomplete → Expired
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.