| Who | When | What | Removed | Added |
|---|---|---|---|---|
| jdinbox | 2011-06-20 18:42:03 PDT | CC | dolske | |
| g.maone | 2011-06-20 23:31:45 PDT | CC | g.maone | |
| ludovic | 2011-06-20 23:55:25 PDT | CC | ludovic | |
| gavin.sharp | 2011-06-21 08:04:07 PDT | CC | gavin.sharp | |
| albill | 2011-06-21 16:26:32 PDT | CC | abillings | |
| dveditz | 2011-06-21 18:05:56 PDT | Summary | Placeholder for Rizzo/Duong SSL attack | Rizzo/Duong chosen plaintext attack on SSL/TLS 1.0 (facilitated by websockets) |
| Assignee | nobody | bsmith | ||
| CC | kaie, rrelyea, wtc | |||
| dveditz | 2011-06-21 18:11:19 PDT | tracking-firefox6 | --- | + |
| tracking-firefox7 | --- | + | ||
| status-firefox6 | --- | affected | ||
| status-firefox7 | --- | affected | ||
| brian | 2011-06-21 21:53:32 PDT | CC | mcmanus | |
| brandon | 2011-06-22 10:00:03 PDT | CC | bsterne, thaidn | |
| wtc | 2011-06-22 11:32:56 PDT | CC | agl | |
| brian | 2011-06-24 01:39:48 PDT | Attachment #541628 Flags | review?(rrelyea), superreview?(wtc), feedback?(agl) | |
| brian | 2011-06-24 01:48:50 PDT | Attachment #541628 Attachment is obsolete | 0 | 1 |
| Attachment #541632 Flags | review?(rrelyea), superreview?(wtc), feedback?(agl) | |||
| Attachment #541628 Flags | review?(rrelyea), superreview?(wtc), feedback?(agl) | |||
| brandon | 2011-06-24 10:25:29 PDT | CC | juliano | |
| brian | 2011-06-24 11:05:35 PDT | Attachment #541721 Flags | review?(rrelyea) | |
| brian | 2011-06-24 11:57:38 PDT | CC | nelson | |
| nelson | 2011-06-24 12:54:47 PDT | Product | Core | NSS |
| Version | unspecified | 3.12 | ||
| Component | Security | Libraries | ||
| QA Contact | toolkit | libraries | ||
| rrelyea | 2011-06-24 16:28:12 PDT | Attachment #541632 Flags | review?(rrelyea) | review+ |
| rrelyea | 2011-06-24 16:33:10 PDT | Attachment #541721 Flags | review?(rrelyea) | review+ |
| brian | 2011-06-25 23:29:39 PDT | Attachment #541632 Attachment is obsolete | 0 | 1 |
| Attachment #541721 Attachment is obsolete | 0 | 1 | ||
| Attachment #541996 Flags | review?(wtc), feedback?(agl) | |||
| Attachment #541632 Flags | superreview?(wtc), feedback?(agl) | |||
| agl | 2011-06-27 06:33:47 PDT | Attachment #541996 Flags | feedback?(agl) | feedback+ |
| brian | 2011-06-27 18:04:04 PDT | Attachment #541996 Attachment is obsolete | 0 | 1 |
| Attachment #542352 Flags | review?(wtc) | |||
| Attachment #541996 Flags | review?(wtc) | |||
| wtc | 2011-06-27 18:27:06 PDT | Attachment #542352 Flags | review?(wtc) | review- |
| brian | 2011-06-27 23:59:55 PDT | Attachment #542352 Attachment is obsolete | 0 | 1 |
| Attachment #542392 Flags | review?(wtc) | |||
| brian | 2011-06-28 00:07:12 PDT | Attachment #542392 Attachment is obsolete | 0 | 1 |
| Attachment #542393 Flags | review?(wtc) | |||
| Attachment #542392 Flags | review?(wtc) | |||
| wtc | 2011-06-28 12:43:58 PDT | Attachment #542393 Flags | review?(wtc) | review+ |
| dveditz | 2011-06-29 16:40:21 PDT | Whiteboard | [sg:moderate] not vuln by default currently | |
| Summary | Rizzo/Duong chosen plaintext attack on SSL/TLS 1.0 (facilitated by websockets) | Rizzo/Duong chosen plaintext attack on SSL/TLS 1.0 (facilitated by websockets -76) | ||
| christophe.ravel.bugs | 2011-06-30 09:49:16 PDT | CC | christophe.ravel.bugs | |
| christophe.ravel.bugs | 2011-07-01 09:10:42 PDT | CC | Xuelei.Su | |
| christophe.ravel.bugs | 2011-07-06 08:25:19 PDT | CC | bradford.wetmore | |
| brian | 2011-07-09 10:35:55 PDT | Attachment #542393 Attachment is obsolete | 0 | 1 |
| Attachment #545005 Flags | review?(wtc) | |||
| brian | 2011-07-09 11:13:24 PDT | Depends on | 668001 | |
| brian | 2011-07-09 11:13:54 PDT | Target Milestone | --- | 3.12.11 |
| asa | 2011-07-17 23:39:26 PDT | CC | asa | |
| dveditz | 2011-07-22 23:55:52 PDT | CC | dveditz, reed | |
| alvolkov.bgs | 2011-07-27 18:33:18 PDT | CC | alvolkov.bgs, eay | |
| asa | 2011-08-05 20:51:28 PDT | CC | asa | |
| brian | 2011-08-08 19:16:27 PDT | CC | v-smanzu | |
| dveditz | 2011-08-10 11:23:02 PDT | tracking-firefox6 | + | - |
| status-firefox6 | affected | wontfix | ||
| wtc | 2011-08-10 18:59:15 PDT | Attachment #545005 Attachment is obsolete | 0 | 1 |
| Attachment #545005 Flags | review?(wtc) | |||
| wtc | 2011-08-12 10:30:47 PDT | Target Milestone | 3.12.11 | 3.13 |
| ginnchen+exoracle | 2011-09-02 00:39:20 PDT | CC | ginn.chen | |
| kairo | 2011-09-06 12:04:18 PDT | CC | kairo | |
| bugzilla | 2011-09-06 12:44:11 PDT | CC | johnath | |
| brian | 2011-09-07 22:52:08 PDT | CC | ekr | |
| christian | 2011-09-15 14:50:59 PDT | CC | clegnitto | |
| jwalden | 2011-09-19 11:27:11 PDT | CC | jwalden+bmo | |
| spectre | 2011-09-20 07:55:16 PDT | CC | spectre | |
| jruderman | 2011-09-20 10:09:48 PDT | Whiteboard | [sg:moderate] not vuln by default currently | [sg:high] vuln if plugins are enabled |
| ian.melven | 2011-09-20 10:16:07 PDT | CC | choller, imelven | |
| josh | 2011-09-20 12:22:51 PDT | CC | josh | |
| brendan | 2011-09-20 13:42:23 PDT | CC | brendan | |
| gal | 2011-09-20 13:45:55 PDT | CC | gal | |
| brian | 2011-09-20 14:29:16 PDT | Whiteboard | [sg:high] vuln if plugins are enabled | [sg:high] |
| Version | 3.12 | trunk | ||
| Hardware | x86 | All | ||
| OS | Mac OS X | All | ||
| alvolkov.bgs | 2011-09-21 17:28:47 PDT | CC | julien.pierre | |
| brian | 2011-09-21 20:05:42 PDT | Attachment #561647 Flags | review?(wtc), superreview?(rrelyea), feedback? | |
| reed | 2011-09-22 09:16:37 PDT | Alias | CVE-2011-3389 | |
| brian | 2011-09-23 09:58:11 PDT | Attachment #561647 Flags | feedback? | feedback?(agl), feedback?(Xuelei.Su) |
| agl | 2011-09-23 10:08:08 PDT | Attachment #561647 Flags | feedback?(agl) | feedback+ |
| brian | 2011-09-23 23:30:48 PDT | Whiteboard | [sg:high] | [sg:moderate?] |
| dveditz | 2011-09-26 12:00:56 PDT | Group | core-security | |
| mh+mozilla | 2011-09-26 12:37:03 PDT | CC | mh+mozilla | |
| bugzilla1 | 2011-09-26 15:54:15 PDT | CC | bugzilla | |
| khillman | 2011-09-26 23:52:46 PDT | CC | khillman | |
| bugs+mozilla-unused | 2011-09-27 04:52:37 PDT | CC | stoile | |
| jwatt | 2011-09-27 05:06:08 PDT | CC | jwatt | |
| R.Kelley.Cook | 2011-09-27 06:17:31 PDT | CC | R.Kelley.Cook | |
| bugzilla.spam2 | 2011-09-27 07:08:24 PDT | CC | bugzilla.spam2 | |
| johnp | 2011-09-27 07:21:40 PDT | CC | johnp | |
| al_9x | 2011-09-27 14:55:33 PDT | CC | al_9x | |
| brian | 2011-09-28 00:50:07 PDT | Attachment #552285 Attachment is obsolete | 0 | 1 |
| Attachment #561647 Attachment is obsolete | 0 | 1 | ||
| Attachment #562997 Flags | review?(wtc) | |||
| Attachment #561647 Flags | review?(wtc), superreview?(rrelyea), feedback?(Xuelei.Su) | |||
| brian | 2011-09-28 00:52:17 PDT | Attachment #562997 Attachment is patch | 0 | 1 |
| brian | 2011-09-28 00:59:34 PDT | Attachment #562997 Attachment is obsolete | 0 | 1 |
| Attachment #562999 Flags | review?(wtc) | |||
| Attachment #562997 Flags | review?(wtc) | |||
| n-roeser | 2011-09-28 03:40:35 PDT | CC | n-roeser | |
| mozilla | 2011-09-28 12:26:19 PDT | CC | mozilla | |
| wtc | 2011-09-28 15:05:04 PDT | Attachment #562999 Flags | review?(wtc) | review+ |
| d_king | 2011-09-28 23:17:38 PDT | CC | dgk | |
| bugzilla | 2011-09-29 01:43:29 PDT | CC | bugzilla | |
| ian.melven | 2011-09-29 16:52:05 PDT | See Also | CVE-2011-3389 | |
| ian.melven | 2011-09-29 16:52:33 PDT | See Also | CVE-2011-3389 | |
| mkmelin+mozilla | 2011-09-30 04:51:15 PDT | CC | mkmelin+mozilla | |
| brian | 2011-09-30 10:53:39 PDT | Attachment #562999 Attachment is obsolete | 0 | 1 |
| Attachment #563777 Flags | superreview?(rrelyea) | |||
| brian | 2011-09-30 10:54:37 PDT | Attachment #563777 Attachment is patch | 0 | 1 |
| wtc | 2011-09-30 11:11:12 PDT | Attachment #563777 Flags | review+ | |
| dewmigg | 2011-09-30 15:35:57 PDT | CC | dewmigg | |
| rrelyea | 2011-09-30 16:21:00 PDT | Attachment #563777 Flags | superreview?(rrelyea) | superreview+ |
| andy44 | 2011-10-01 06:12:55 PDT | CC | andy44 | |
| andy44 | 2011-10-01 06:54:39 PDT | CC | andy44 | |
| brian | 2011-10-02 22:28:41 PDT | Status | NEW | RESOLVED |
| Resolution | --- | FIXED | ||
| Closed | 2011-10-03 05:28:41 | |||
| rrelyea | 2011-10-06 09:58:10 PDT | CC | emaldona | |
| brian | 2011-10-06 19:47:45 PDT | Summary | Rizzo/Duong chosen plaintext attack on SSL/TLS 1.0 (facilitated by websockets -76) | Rizzo/Duong chosen plaintext attack (BEAST) on SSL/TLS 1.0 (facilitated by websockets -76) |
| mozillabugs | 2011-10-09 02:16:16 PDT | CC | mozillabugs | |
| julien.pierre | 2011-10-20 15:52:42 PDT | CC | gregory.simons | |
| christophe.ravel.bugs | 2011-10-24 16:32:38 PDT | CC | tnzzbugs | |
| kaie | 2011-11-24 05:20:05 PST | Blocks | 702111 | |
| bzbarsky | 2011-11-24 11:17:38 PST | Depends on | 702111 | |
| Blocks | 702111 | |||
| honzab.moz | 2011-12-06 15:37:02 PST | CC | honzab.moz | |
| quel | 2011-12-11 22:35:21 PST | CC | quel | |
| kdudka | 2011-12-27 05:14:15 PST | CC | kdudka | |
| chemobejk | 2011-12-30 04:48:43 PST | CC | chemobejk | |
| t8m | 2012-01-02 08:50:21 PST | CC | t8m | |
| rforbes | 2013-07-19 18:31:57 PDT | CC | rforbes | |
| Flags | sec-bounty+ |