Bugzilla – Bug 862360
VUL-0: CVE-2014-1483: Firefox/Seamonkey: Information disclosure with *FromPoint on iframes
Last modified: 2014-03-26 09:12:14 UTC
CVE-2014-1483 Security researcher Jordan Milne reported an information leak where document.caretPositionFromPoint and document.elementFromPoint functions could be used on a cross-origin iframe to gain information on the iframe's DOM and other attributes through a timing attack, violating same-origin policy. References: http://www.mozilla.org/security/announce/2014/mfsa2014-05.html http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-1483 https://bugzilla.redhat.com/show_bug.cgi?id=1060943
bugbot adjusting priority
we shipped firefox 28