关键漏洞信息 漏洞名称: Image stealing via canvas and HTTP redirect 公告日期: November 12, 2008 报告者: Georgi Guninski, Michal Zalewski, Chris Evans 影响: High 受影响的产品: Firefox, SeaMonkey, Thunderbird 修复版本: - Firefox 2.0.0.18 - SeaMonkey 1.1.13 - Thunderbird 2.0.0.18 描述: MozilladeveloperGeorgiGuninskireportedthatthecanvaselementcouldbeusedinconjunctionwithanHTTPredirecttobypasssame-originrestrictionsandgainaccesstothecontentinarbitraryimagesfromotherdomains. Thisvulnerabilitycouldbeusedbyanattackertostealprivateinformationfromavictimwhoisloggedintoawebsitestoresthedatainimages. SecurityresearchersMichalZalewskiandChrisEvensalsoreportedanadditionalthreatausedbytisvulnerabilityinwhichanattackercanenumeratethesoftwareinstalledonavictim’scomputerbyusingmoz-iconastheredirectiontarget. 不受影响的产品: Firefox 3