Comment 7 for bug 1002439

Revision history for this message
Ted Gould (ted) wrote : Re: [Bug 1002439] Re: XML entity vulnerabilities in 0.48.2 (r9819)

On Sat, 2012-06-23 at 17:17 +0000, Marc Deslauriers wrote:
> Ted, have you looked at this issue? Do you have a fix in mind?

Yes, Jon talked to me about it. I think his proposed fix is reasonable,
unfortunately it disables a feature that some people might use, though I
haven't found anyone using it for good.

I think probably the "right" fix is to prompt the user with a dialog
that says: "Hey, this document wants to download random content from the
web, are you sure about that?" I was looking at that, but didn't find
an easy way to do it.

So, in a nutshell, I'm all for just disabling it and seeing who
complains. I'm betting I was just over thinking it.