Open Bug 1207968 Opened 10 years ago Updated 7 years ago

pkcs#11 password enter dialog is opened twice for the same password/PIN - not thread safe?

Categories

(Thunderbird :: Security, defect)

38 Branch
defect
Not set
critical

Tracking

(Not tracked)

UNCONFIRMED

People

(Reporter: jpstotz, Unassigned)

Details

(Keywords: hang)

Attachments

(1 file)

Attached image pkcs#11-pwd-dialog.png
User Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/45.0.2454.85 Safari/537.36 OPR/32.0.1948.25 Steps to reproduce: On Thunderbird with installed PKCS#11 library (e.g. for a smart card) a password dialog is shown in case the PKCS#11 library/smart card requires a PIN before access is granted to the smart card. This password enter dialog seems to be not thread safe as it can appear twice over another. The second dialog becomes visible if you move the first dialog away. Note that this behavior only occurs in case certain add-ons are installed in Thunderbird, e.g. “Allow HTML Temp” 3.6.4 by Alexander Ihrig. Actual results: When clicking a S/MIME encrypted mail the password enter dialog for the pkcs#11 module appears twice. Expected results: Thunderbird should only display one password dialog at a time per pkcs#11 module.
jpstotz Do you still see this when using a current version?
Component: Untriaged → Security
Flags: needinfo?(jpstotz)
Unfortunately yes. There was no positive change since I created this bug report. It even got worse because in situations when this bug occurs there is a 50/50 chance that the whole Thunderbird process stops working and I have to kill it.
Flags: needinfo?(jpstotz)

(comment in bug 930497 was meant for this bug)

I thought I recently read something recently about thread safe issue in NSS

Severity: normal → critical
Keywords: hang
Summary: pkcs#11 password enter dialog is opened twice for the same password/PIN → pkcs#11 password enter dialog is opened twice for the same password/PIN - not thread safe?
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: