[Webkit-unassigned] [Bug 12073] SVGSVGElement needs setCurrentTimesupport

bugzilla-daemon at webkit.org bugzilla-daemon at webkit.org
Tue Jan 2 09:50:08 PST 2007


http://bugs.webkit.org/show_bug.cgi?id=12073


ddkilzer at webkit.org changed:

           What    |Removed                     |Added
----------------------------------------------------------------------------
                 CC|                            |ddkilzer at webkit.org




------- Comment #1 from ddkilzer at webkit.org  2007-01-02 09:50 PDT -------
The SVG spec allows one to reset the clock on computer that the "browser" is
running on?  This seems like it could (at the very least) create a
denial-of-service attack on time-sensitive security exchanges (like Kerberos). 
In the worst case, it might even allow replay attacks.

Am I misunderstanding what setCurrentTime() would do?


-- 
Configure bugmail: http://bugs.webkit.org/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are the assignee for the bug, or are watching the assignee.



More information about the webkit-unassigned mailing list