Save file containing environment variables in "Save Link As" on Firefox 111 Windows
Categories
(Firefox :: Security, defect)
Tracking
()
People
(Reporter: haxatron1, Assigned: Gijs)
References
Details
(Keywords: csectype-disclosure, reporter-external, sec-moderate, Whiteboard: [reporter-external] [client-bounty-form] [verif?][adv-main112+][adv-esr102.10+])
Attachments
(3 files)
53 bytes,
text/html
|
Details | |
48 bytes,
text/x-phabricator-request
|
diannaS
:
approval-mozilla-beta+
RyanVM
:
approval-mozilla-esr102+
|
Details | Review |
359 bytes,
text/plain
|
Details |
Not sure if you noticed but its still possible to save files containing %% when using "Save Link As" on Firefox 111.0 -- https://www.mozilla.org/en-US/security/advisories/mfsa2023-09/#CVE-2023-28163
STR
- Right click Save Link As on this document.
o
Assignee | ||
Updated•2 years ago
|
Assignee | ||
Updated•2 years ago
|
Assignee | ||
Comment 3•2 years ago
|
||
Assignee | ||
Comment 4•2 years ago
|
||
CVE-2023-28163 was sec-moderate, so I don't see this being more - arguably it's sec-low because it requires more user action than "just" downloading something (which can be site-triggered, whereas the STR here require the context menu), though the older bug required configuration, so 🤷♂️. I've picked sec-moderate for now, but given that I don't see this being sec-high, going to assume I'm OK to land and uplift this...
Comment 5•2 years ago
|
||
Assignee | ||
Comment 6•2 years ago
|
||
Comment on attachment 9323977 [details]
Bug 1823077, r?mhowell
Beta/Release Uplift Approval Request
- User impact if declined: sec-moderate
- Is this code covered by automated tests?: No
- Has the fix been verified in Nightly?: No
- Needs manual test from QE?: Yes
- If yes, steps to reproduce: See comment 0
- List of other uplifts needed: n/a
- Risk to taking this patch: Low
- Why is the change risky/not risky? (and alternatives if risky): Very small patch in targeted bit of the windows filepicker code
- String changes made/needed: Nope
- Is Android affected?: No
Assignee | ||
Updated•2 years ago
|
Assignee | ||
Comment 7•2 years ago
|
||
Comment on attachment 9323977 [details]
Bug 1823077, r?mhowell
ESR Uplift Approval Request
- If this is not a sec:{high,crit} bug, please state case for ESR consideration: sec-moderate
- User impact if declined: ditto
- Fix Landed on Version: 113 w/ beta uplift 112 requested
- Risk to taking this patch: Low
- Why is the change risky/not risky? (and alternatives if risky): Very small patch in targeted bit of the windows filepicker code
Comment 8•2 years ago
|
||
yes, moderate sounds right.
Updated•2 years ago
|
Comment 9•2 years ago
|
||
Comment on attachment 9323977 [details]
Bug 1823077, r?mhowell
Approved for 112.0b6
Comment 10•2 years ago
|
||
uplift |
Comment 11•2 years ago
|
||
I have reproduced the bug on Win 11 with an affected Nightly build 113.0a1 (2023-03-17).
The issue is verified as fixed on latest Nightly 113.0a1 and Beta 112.0b6 under Win 11 x64. I'll verify the bug in Esr as well, if the patch is approved.
Comment 12•2 years ago
|
||
Comment on attachment 9323977 [details]
Bug 1823077, r?mhowell
Approved for 102.10esr.
Comment 13•2 years ago
|
||
uplift |
Comment 14•2 years ago
|
||
This is also verified as fixed on 102.10.0esr with Win 11 x64.
Updated•2 years ago
|
Updated•2 years ago
|
Comment 15•2 years ago
|
||
Updated•2 years ago
|
Updated•1 year ago
|
Updated•6 months ago
|
Description
•