mirror of
https://github.com/arkenfox/user.js.git
synced 2025-12-01 19:14:51 -05:00
update pdfjs CVEs info
This commit is contained in:
parent
c90135cf86
commit
4e94234f46
1 changed files with 2 additions and 1 deletions
3
user.js
3
user.js
|
|
@ -536,7 +536,8 @@ user_pref("network.IDN_show_punycode", true);
|
|||
/* 2620: enforce PDFJS, disable PDFJS scripting
|
||||
* This setting controls if the option "Display in Firefox" is available in the setting below
|
||||
* and by effect controls whether PDFs are handled in-browser or externally ("Ask" or "Open With")
|
||||
* [WHY] pdfjs is lightweight, open source, and secure: the last exploit was June 2015 [1]
|
||||
* [WHY] pdfjs is lightweight, open source, and secure: In the last 10 years it has only had
|
||||
* two known exploits, both in 2024: one 'Severe' and one 'Important' [1]
|
||||
* It doesn't break "state separation" of browser content (by not sharing with OS, independent apps).
|
||||
* It maintains disk avoidance and application data isolation. It's convenient. You can still save to disk.
|
||||
* [NOTE] JS can still force a pdf to open in-browser by bundling its own code
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue