<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0">
	<channel>
		<title><![CDATA[FireGPG Forum - Security update: 0.4.7]]></title>
		<link>http://forum.getfiregpg.org/viewtopic.php?id=264</link>
		<description><![CDATA[The most recent posts in Security update: 0.4.7.]]></description>
		<lastBuildDate>Wed, 26 Dec 2007 16:49:27 +0000</lastBuildDate>
		<generator>PunBB</generator>
		<item>
			<title><![CDATA[Re: Security update: 0.4.7]]></title>
			<link>http://forum.getfiregpg.org/viewtopic.php?pid=863#p863</link>
			<description><![CDATA[<p>More info regarding the security issue can be found at <a href="http://blog.watchfire.com/wfblog/2007/12/firegpg-046-gma.html">http://blog.watchfire.com/wfblog/2007/1 &#133; 6-gma.html</a></p>]]></description>
			<author><![CDATA[dummy@example.com (roeeh)]]></author>
			<pubDate>Wed, 26 Dec 2007 16:49:27 +0000</pubDate>
			<guid>http://forum.getfiregpg.org/viewtopic.php?pid=863#p863</guid>
		</item>
		<item>
			<title><![CDATA[Security update: 0.4.7]]></title>
			<link>http://forum.getfiregpg.org/viewtopic.php?pid=859#p859</link>
			<description><![CDATA[<p>A new version dues to a (small) security problem, who come with smalls improvents <img src="http://forum.getfiregpg.org/img/smilies/smile.png" width="15" height="15" alt="smile" />.</p><p>Many users ask for a support of FireFox 3. We will support at last when the final version will be relased, before if we have the time ^^<br />Bugs :</p><p>&nbsp; &nbsp; * Fixed a (small) security problem (reported by Roee Hay, IBM).</p><div class="quotebox"><blockquote><p>FireGPG (tested on 0.4.6) suffers from a Cross-Site-Scripting flaw affecting gmail.</p><p>Normally, After FireGPG automatically verifies signed mails in Gmail, it prints the public key issuer name underneath the mail message (i.e: &quot;Good sign from Roee Hay&nbsp; (made the 2007 17:26:52)&quot;.</p><p>However, the issuer name is not sanitized or verified, a fact which leads to an XSS vulnerability. If the issuer name contains a malicious javascript (e.g: &quot;&lt;script&gt; [XSS_PAYLOAD] &lt;/script&gt;&quot;), it will be executed under Gmail&#039;s context, thus giving the attacker an opportunity to steal the victim&#039;s cookies, mail and so on. It can be exploited by sending the victim a signed message and convincing him to add your malicious public key.</p></blockquote></div><p>* Fixed a problem with the mail autodetect system.</p><p>Functionalities :</p><p>&nbsp; &nbsp; * Improve performances with gmail<br />&nbsp; &nbsp; * Patch of tjm1983 applied, who improve signs for old gmail&#039;s version.</p><p>Locales :</p><p>&nbsp; &nbsp; * English corrections from Sebastien Wains</p><p>Misc :</p><p>&nbsp; &nbsp; * Change the system for upgrades or installs (this page ^^)</p>]]></description>
			<author><![CDATA[dummy@example.com (the_glu)]]></author>
			<pubDate>Tue, 25 Dec 2007 10:31:39 +0000</pubDate>
			<guid>http://forum.getfiregpg.org/viewtopic.php?pid=859#p859</guid>
		</item>
	</channel>
</rss>
