From cef6d7f9ba096c7644bb084fa97584d64359b09d Mon Sep 17 00:00:00 2001 From: "ben%bengoodger.com" Date: Wed, 23 Mar 2005 21:37:16 +0000 Subject: [PATCH] Fix Firebird bugs 217195 (patch by Jesse Ruderman) - security hole in markLinkVisited (exploited with link.href usage) 219875 (patch by Mike Connor) - localize strings for provisional security UI in Advanced Options panel git-svn-id: svn://10.0.0.236/trunk@171092 18797224-902f-48f8-a5cc-f745e15eee43 --- mozilla/toolkit/content/contentAreaUtils.js | 16 ++++++++++++---- 1 file changed, 12 insertions(+), 4 deletions(-) diff --git a/mozilla/toolkit/content/contentAreaUtils.js b/mozilla/toolkit/content/contentAreaUtils.js index b70778c9f79..29d5c058dd5 100644 --- a/mozilla/toolkit/content/contentAreaUtils.js +++ b/mozilla/toolkit/content/contentAreaUtils.js @@ -105,10 +105,18 @@ function markLinkVisited(href, linkNode) .getService(Components.interfaces.nsIGlobalHistory); if (!globalHistory.isVisited(href)) { globalHistory.addPage(href); - var oldHref = linkNode.href; - linkNode.href = ""; - linkNode.href = oldHref; - } + var oldHref = linkNode.getAttribute("href"); + if (typeof oldHref == "string") { + // Use setAttribute instead of direct assignment. + // (bug 217195, bug 187195) + linkNode.setAttribute("href", ""); + linkNode.setAttribute("href", oldHref); + } + else { + // Converting to string implicitly would be a + // minor security hole (similar to bug 202994). + } + } } function urlSecurityCheck(url, doc)