Hi,
Just curious, did NoScript protect against this vulnerability, fixed in Firefox 36.0.4 ?
I can't get access to the Bugzilla page since it's protected, so I don't know whether Javascript must be enabled to exploit this SVG parser (?) flaw.
Privilege escalation through SVG navigation
Privilege escalation through SVG navigation
Mozilla/5.0 (Windows NT 6.1; WOW64; rv:36.0) Gecko/20100101 Firefox/36.0
- Giorgio Maone
- Site Admin
- Posts: 9526
- Joined: Wed Mar 18, 2009 11:22 pm
- Location: Palermo - Italy
- Contact:
Re: Privilege escalation through SVG navigation
Yes, NoScript did protect against it.
The exploit requires JavaScript to be enabled on the attacker's page.
The exploit requires JavaScript to be enabled on the attacker's page.
Mozilla/5.0 (Windows NT 6.3; WOW64; rv:36.0) Gecko/20100101 Firefox/36.0
Re: Privilege escalation through SVG navigation
Yay, thanks for letting me know 

Mozilla/5.0 (Windows NT 6.1; WOW64; rv:36.0) Gecko/20100101 Firefox/36.0