Closed
Bug 1058147
Opened 11 years ago
Closed 5 years ago
Android HttpClient MITM vulnerability
Categories
(Firefox for Android Graveyard :: General, defect, P5)
Tracking
(Not tracked)
RESOLVED
INCOMPLETE
People
(Reporter: rnewman, Unassigned)
References
Details
(Whiteboard: CVE-2014-3577)
http://seclists.org/fulldisclosure/2014/Aug/48
We should explore our options on older Android devices that are vulnerable. I don't think MITM of favicon traffic is critical, but if we use the Android HttpClient layer for update downloads, then :sadface:.
Bug 1058146 covers the use of the ch.boye version in ABS. This bug covers our use of Android's own version in core Fennec.
Updated•11 years ago
|
Group: firefox-core-security, core-security
Updated•11 years ago
|
Group: firefox-core-security, core-security
Depends on: 1432998
Comment 1•7 years ago
|
||
Re-triaging per https://bugzilla.mozilla.org/show_bug.cgi?id=1473195
Needinfo :susheel if you think this bug should be re-triaged.
Priority: -- → P5
Comment 2•5 years ago
|
||
We have completed our launch of our new Firefox on Android. The development of the new versions use GitHub for issue tracking. If the bug report still reproduces in a current version of [Firefox on Android nightly](https://play.google.com/store/apps/details?id=org.mozilla.fenix) an issue can be reported at the [Fenix GitHub project](https://github.com/mozilla-mobile/fenix/). If you want to discuss your report please use [Mozilla's chat](https://wiki.mozilla.org/Matrix#Connect_to_Matrix) server https://chat.mozilla.org and join the [#fenix](https://chat.mozilla.org/#/room/#fenix:mozilla.org) channel.
Status: NEW → RESOLVED
Closed: 5 years ago
Resolution: --- → INCOMPLETE
| Assignee | ||
Updated•5 years ago
|
Product: Firefox for Android → Firefox for Android Graveyard
You need to log in
before you can comment on or make changes to this bug.
Description
•