Episode #848 Quiz
XSinator
Date: 2021-12-07 | Length: 1.5 hrs | Episode page at twit.tv
About this episode
Tavis Ormandy found a memory-corruption bug in Mozilla NSS signature verification, affecting most NSS uses before 3.73/3.68.1 ESR; DER-encoded DSA and RSA-PSS signatures in PDF and email clients could trigger heap overflow, crashing or enabling code execution. Researchers also showed XS-Leaks let hostile pages infer cross-origin user state through browser side channels.
Your name and email are stored only in your browser local storage for convenience. They are not retained server-side.