<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://www.w3.org/Bugs/Public/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.4"
          urlbase="https://www.w3.org/Bugs/Public/"
          
          maintainer="sysbot+bugzilla@w3.org"
>

    <bug>
          <bug_id>16717</bug_id>
          
          <creation_ts>2012-04-12 21:58:00 +0000</creation_ts>
          <short_desc>Security issue with image exclusions</short_desc>
          <delta_ts>2012-04-25 22:21:53 +0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>CSS</product>
          <component>Exclusions</component>
          <version>unspecified</version>
          <rep_platform>PC</rep_platform>
          <op_sys>All</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>DUPLICATE</resolution>
          <dup_id>16112</dup_id>
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords></keywords>
          <priority>P2</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Vincent Hardy">vhardy</reporter>
          <assigned_to name="Vincent Hardy">vhardy</assigned_to>
          <cc>eoconnor</cc>
    
    <cc>ratan</cc>
    
    <cc>stearns</cc>
          
          <qa_contact>public-css-bugzilla</qa_contact>

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>66671</commentid>
    <comment_count>0</comment_count>
    <who name="Vincent Hardy">vhardy</who>
    <bug_when>2012-04-12 21:58:00 +0000</bug_when>
    <thetext>The use of images as exclusion areas, especially when combined with the shape-image-threshold property are a security concerns because through script, malicious code could analyze the content of a cross domain image.

For example, if the attacker uses 1px x 1px inline elements around and inside an image exclusion and uses script to find the position of the element, information about the image will be leaked and will allow reconstruction of a grayscale version of the image.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>67072</commentid>
    <comment_count>1</comment_count>
    <who name="Alan Stearns">stearns</who>
    <bug_when>2012-04-25 22:21:53 +0000</bug_when>
    <thetext>Copying the above comment to 16112

*** This bug has been marked as a duplicate of bug 16112 ***</thetext>
  </long_desc>
      
      

    </bug>

</bugzilla>