[Pkg-mozext-maintainers] Bug#734999: [security] https-everywhere might allow spoofing

Elrond elrond+bugs.debian.org at samba-tng.org
Sat Jan 11 17:36:53 UTC 2014


Package: xul-ext-https-everywhere
Version: 3.4.1-1~bpo70+1
Tags: wheezy jessie

According to

    https://trac.torproject.org/projects/tor/ticket/5477

when using https-everywhere on firefox before 20 might
allow spoofing of some domains.

I am not sure, whether current https-everywhere versions
have any workarounds for earlier firefox versions. If they
actually have, please excuse this bugreport!

This bug mainly affects stable/bpo and testing, as unstable
has firefox>=20.


    Elrond



More information about the Pkg-mozext-maintainers mailing list