RCE via "copy as curl" on mac
Categories
(DevTools :: Netmonitor, defect)
Tracking
(firefox-esr60 wontfix, firefox64 wontfix, firefox65 wontfix, firefox66 verified)
People
(Reporter: watashiwaher, Assigned: bgrins)
References
Details
(4 keywords, Whiteboard: [reporter-external] [client-bounty-form] [verif?][post-critsmash-triage]][adv-main66+])
Attachments
(2 files)
Comment 1•6 years ago
|
||
Comment 3•6 years ago
|
||
Updated•6 years ago
|
Assignee | ||
Comment 5•6 years ago
|
||
I'm assuming this was the fix in Web Inspector: https://github.com/WebKit/webkit/commit/5736bda9ad07609ef386e2d5a7f5308c17b98586.
I can't find any reference to a commit from https://support.apple.com/en-us/HT208324, or a commit with the the CVE ID.
Assignee | ||
Comment 6•6 years ago
|
||
Scanning our netmonitor code for "copy as curl", this looks like the relevant function: https://searchfox.org/mozilla-central/rev/b29663c6c9c61b0bf29e8add490cbd6bad293a67/devtools/client/shared/curl.js#348
Assignee | ||
Comment 7•6 years ago
|
||
Assignee | ||
Comment 8•6 years ago
|
||
I've ported over the WebInspector fix in attachment 9036477 [details]
![]() |
||
Comment 9•6 years ago
|
||
https://hg.mozilla.org/integration/autoland/rev/10d517464fb1ba1ea73ddcaea039e32f4f4116f6
https://hg.mozilla.org/mozilla-central/rev/10d517464fb1
Comment 10•6 years ago
|
||
Too late for Fx65 in light of tomorrow's RC gtb. Let's let this ride the trains with 66.
Updated•6 years ago
|
Updated•6 years ago
|
Updated•6 years ago
|
Comment 11•6 years ago
|
||
I have managed to reproduce the issue mentioned in comment 0 using Firefox 65.0.1 (BuildId:20190211233335).
This issue is verified fixed using Firefox 66.0b9 (BuildId:20190218131312) on macOS 10.12.6
Assignee | ||
Comment 12•6 years ago
|
||
Daniel, do you think we should uplift this to ESR for the 60.6 release?
Comment 13•6 years ago
|
||
I don't feed strongly about it. It's a simple fix that release-drivers would probably take, but how many people are doing web development on ESR, let alone on ESR on mac?
Assignee | ||
Comment 14•6 years ago
|
||
(In reply to Daniel Veditz [:dveditz] from comment #13)
I don't feed strongly about it. It's a simple fix that release-drivers would probably take, but how many people are doing web development on ESR, let alone on ESR on mac?
That's a good point. Given that this is DevTools + OSX only, I'm leaning towards not taking the resources required to get this uplifted and tested onto 60.
Updated•6 years ago
|
Updated•6 years ago
|
Comment 15•6 years ago
|
||
Is the report to Bash in a public report somewhere? I'd like to link to it.
Updated•5 years ago
|
Updated•5 years ago
|
Updated•9 months ago
|
Description
•