Looking into this issue for Linspire Internet Suite we maintain, looks
like the fix for this exploit
http://secunia.com/multiple_browsers_frame_injection_vulnerability_test/
is just a simple pref setting ...
pref("browser.frame.validate_origin", true);
--pete
--
Pete Collins - Founder, Mozdev Group Inc.
www.mozdevgroup.com
Mozilla Software Development Solutions
_______________________________________________
Mozilla-security mailing list
[email protected]
http://mail.mozilla.org/listinfo/mozilla-security