Closed
Bug 1125483
Opened 10 years ago
Closed 10 years ago
Arbitrary code execution using bug 1120261 and bug 1110614
Categories
(Core :: XPConnect, defect)
Tracking
()
RESOLVED
FIXED
mozilla35
People
(Reporter: moz_bug_r_a4, Assigned: bholley)
References
Details
(Keywords: reporter-external, sec-high, verifyme, Whiteboard: [b2g-adv-main2.2-])
I'm filing this bug to attach a testcase that is a combination of bug 1120261 and bug 1110614.
The reason the remote code execution PoC in bug 1120261 does not work on 31.4.0esr is that bug 1092388 is fixed on 31.4.0esr, so the remote code execution PoC can work on 31.4.0esr by using bug 1110614 instead of bug 1092388.
| Reporter | ||
Comment 1•10 years ago
|
||
This works on 31.4.0esr.
Updated•10 years ago
|
| Assignee | ||
Comment 2•10 years ago
|
||
This is great, and will be very helpful for QA - thanks moz_bug_r_a4.
Al, this isn't a new bug - it's just a more useful testcase for esr31 for the bugs we have on file already.
Either bug 1125015 or bug 1110614 should fix this (and we plan to land both).
Comment 3•10 years ago
|
||
We'll consider some bounty here based on the work when the committee meets. We do appreciate the continued attention on these issues.
Flags: sec-bounty- → sec-bounty?
Updated•10 years ago
|
Group: dom-core-security
Comment 4•10 years ago
|
||
Bobby, I can close this, right?
| Assignee | ||
Comment 5•10 years ago
|
||
(In reply to Andrew McCreight [:mccr8] from comment #4)
> Bobby, I can close this, right?
Yep. We should definitely verify it though.
Flags: needinfo?(bobbyholley)
Keywords: verifyme
Updated•10 years ago
|
Status: NEW → RESOLVED
Closed: 10 years ago
Resolution: --- → FIXED
Updated•10 years ago
|
Component: Security → XPConnect
Updated•10 years ago
|
Flags: sec-bounty? → sec-bounty+
Updated•10 years ago
|
Group: dom-core-security
Updated•10 years ago
|
status-b2g-v1.4:
--- → unaffected
status-b2g-v2.0:
--- → fixed
status-b2g-v2.0M:
--- → fixed
status-b2g-v2.1:
--- → fixed
status-b2g-v2.1S:
--- → fixed
status-b2g-v2.2:
--- → fixed
Target Milestone: --- → mozilla35
Updated•10 years ago
|
Whiteboard: [b2g-adv-main2.2?]
Comment 6•10 years ago
|
||
Ryan, this bug has status-b2g-v2.2 fixed despite both dependencies having status-b2g-v2.2 unaffected. Could you shed some light on this?
Flags: needinfo?(ryanvm)
Whiteboard: [b2g-adv-main2.2?] → [b2g-adv-main2.2-]
Updated•10 years ago
|
status-b2g-v2.2:
fixed → ---
Flags: needinfo?(ryanvm)
Updated•10 years ago
|
Group: core-security → core-security-release
Updated•9 years ago
|
Group: core-security-release
Updated•1 year ago
|
Keywords: reporter-external
You need to log in
before you can comment on or make changes to this bug.
Description
•