Re: [Tails-dev] MFSA 2015-78 (aka. CVE-2015-4495) vs. Tails

Delete this message

Reply to this message
Author: intrigeri
Date:  
To: The Tails public development discussion list
Subject: Re: [Tails-dev] MFSA 2015-78 (aka. CVE-2015-4495) vs. Tails
Romeo Papa wrote (07 Aug 2015 23:04:15 GMT) :
> PDF.js can be disabled as follows:


>     1. Type about:config in the Firefox address bar
>     2. Search for the pdfjs.disabled entry
>     3. Set the pdfjs.disabled entry to True


https://bugzilla.mozilla.org/show_bug.cgi?id=1179262#c30 reads:
"Notice that "pdfjs.disabled" shall not be used, at least without
switching the handler." Not sure how one would "switch the handler",
and perhaps it doesn't mean what I think anyway.

Romeo Papa, do you want to research this further? It would be very
useful to add a mitigation measure when mentioning this security issue
in the "Known issues" section of the 1.5~rc1 call for testing.

Cheers,
--
intrigeri