forbid @font-face still necessary?
Posted: Tue Jun 14, 2011 10:39 am
Hi
NoScript forbids @font-face because a maliciously crafted font could exploit the font parsers that are rather old. Indeed, there has been such a vulnerability, see MFSA 2010-08: WOFF heap corruption due to integer overflow (see also hackademix.net » Why NoScript Blocks Web Fonts).
But is this precaution still necessary? With Firefox 3.6.13, Firefox has added the OTS font sanitizer, see MFSA 2010-78: Add support for OTS font sanitizer. This means that potentially vulnerable parts of fonts are blocked. Would this not mean that it is now safe for NoScript to switch on @font-face support by default?
--
grüess
mach
NoScript forbids @font-face because a maliciously crafted font could exploit the font parsers that are rather old. Indeed, there has been such a vulnerability, see MFSA 2010-08: WOFF heap corruption due to integer overflow (see also hackademix.net » Why NoScript Blocks Web Fonts).
But is this precaution still necessary? With Firefox 3.6.13, Firefox has added the OTS font sanitizer, see MFSA 2010-78: Add support for OTS font sanitizer. This means that potentially vulnerable parts of fonts are blocked. Would this not mean that it is now safe for NoScript to switch on @font-face support by default?
--
grüess
mach