Closed Bug 1256370 Opened 8 years ago Closed 2 years ago

Audit PNecko IPDL protocol for security vulnerabilities

Categories

(Core :: Networking, defect, P3)

defect

Tracking

()

RESOLVED INCOMPLETE

People

(Reporter: tedd, Unassigned)

References

Details

(Keywords: sec-audit, Whiteboard: [necko-backlog])

This bug is to track the auditing process of the PNecko protocol (as part of Bug 1041862).

The goal is to look at the parent code that is reachable through the PNecko protocol and audit for any potential security vulnerabilities. 

This effort should help reduce the attack surface for privilege escalation once a unprivileged child has been compromised.
This feels like it should be in Necko.
Component: IPC → Networking
(In reply to Andrew Overholt [:overholt] from comment #1)
> This feels like it should be in Necko.

FYI, see also bug 1041862 for explanation. This is a forward looking exercise to investigate the security of our IPC mechanisms, with a view to eventually having a security sandbox.
Whiteboard: [necko-backlog]
Bulk change to priority: https://bugzilla.mozilla.org/show_bug.cgi?id=1399258
Priority: -- → P1
Bulk change to priority: https://bugzilla.mozilla.org/show_bug.cgi?id=1399258
Priority: P1 → P3
Assignee: julian.r.hector → nobody
Status: NEW → RESOLVED
Closed: 2 years ago
Resolution: --- → INCOMPLETE
You need to log in before you can comment on or make changes to this bug.