Closed Bug 1602474 Opened 6 years ago Closed 6 years ago

Kill netscape.security.PrivilegeManager.enablePrivilege

Categories

(Firefox :: Security, task, P2)

task

Tracking

()

RESOLVED DUPLICATE of bug 1448967

People

(Reporter: freddy, Unassigned)

References

Details

(Keywords: sec-want)

We should kill netscape.security.PrivilegeManager.enablePrivilege.

Common exploits for security bugs usually use a memory safety issue to build a arbitrary memory read/write privilege. With this privilege, attackers can overwrite prefs or static variables to gain system principal with netscape.security.PrivilegeManager.enablePrivilege.

Example:
The exploit at https://github.com/0vercl0k/CVE-2019-11708/blob/1cdf26140f17de8a620e90f4f6ea3865e18e49ad/ff-toolbox.js#L653-L680 is using a memory corruption bug to get arbitrary read/write .

Keywords: sec-vector

I don't know if you want to link them to public bugs, but there's been a lot of prior work in this category. Bug 1448967 is about removing it entirely, and it depends on bug 462483 for removing it from Mochitests (maybe that can be fixed now?) and bug 1435113 for removing it from Talos. I started on the latter, but I stalled out on it. I think :emk has done the most recent hardening work on enablePrivilege.

(The latter two bugs have some relevant open bugs, of course.)

Priority: -- → P2

Of course we should nuke enablePrivilege from orbit, but I'm not sure what is the problem here. If the attacker can use exploits like CVE-2019-11708 to execute arbitrary code such as arbitrary read/write, we already lose the battle.

(In reply to Masatoshi Kimura [:emk] from comment #3)

Of course we should nuke enablePrivilege from orbit, but I'm not sure what is the problem here. If the attacker can use exploits like CVE-2019-11708 to execute arbitrary code such as arbitrary read/write, we already lose the battle.

Yes. This is about killing simple exploit chains.
The goal is to increase the amount of work required to go from memory safety issue and arbitrary read/write to full compromise for upcoming security issues. Enabling privileged "chrome" JavaScript execution shouldn't be as simple as flipping a byte.

I have removed enablePrivilege .

Status: NEW → RESOLVED
Closed: 6 years ago
Resolution: --- → DUPLICATE
Group: firefox-core-security
You need to log in before you can comment on or make changes to this bug.