Skip to content
Snippets Groups Projects
Commit 1bfbd7cc authored by Yawning Angel's avatar Yawning Angel
Browse files

Bug 22648: Prevent the "easy" to fix X11 related sandbox escapes.

Per Jann Horn of Google Project Zero, there's a few trivial ways to do
horrific things via the X11 socket, because of the X protocol.

This hopefully closes some of them off by imposing a whitelist on X11
protocol extensions.

Note that it is likely that Firefox can still do horrific things via
X11, so this will need to be improved over time, but, as the README.md
says:

   There are several unresolved issues that affect security and
   fingerprinting.  Do not assume that this is perfect, merely
   "an improvement over nothing".
parent 02f611d5
No related branches found
No related tags found
No related merge requests found
Loading
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment