Closed Bug 1828259 (CVE-2024-5698) Opened 2 years ago Closed 1 year ago

Datalist option overlap url address bar after exiting full screen

Categories

(Core :: DOM: Core & HTML, defect, P3)

defect

Tracking

()

RESOLVED FIXED
127 Branch
Tracking Status
firefox-esr115 - wontfix
firefox122 --- wontfix
firefox123 - wontfix
firefox124 - wontfix
firefox125 --- wontfix
firefox126 --- wontfix
firefox127 + fixed

People

(Reporter: sas.kunz, Assigned: edgar)

References

Details

(Keywords: csectype-spoof, reporter-external, sec-low, Whiteboard: [reporter-external] [client-bounty-form] [verif?][adv-main127+])

Attachments

(4 files, 1 obsolete file)

after fixed on https://bugzilla.mozilla.org/show_bug.cgi?id=1826622, i found other way to make the option overlap the url address bar

step to produces

  1. open http://103.186.0.20/dtlist.html or dtlist.html
  2. press fn+ f11 to fullscreen
  3. press h on datalist.
    4 press fn+ f11 to exit fullscreen, then the option overlap on address bar

tested on 114.0a1 (2023-04-14) (64-bit) (windows 10 home)

Flags: sec-bounty?
Attached file dtlist.html
Group: firefox-core-security → core-security
Component: Security → Layout: Form Controls
Product: Firefox → Core

I'll give this a more specific description to distinguish it from the other bug

Group: core-security → layout-core-security
Keywords: csectype-spoof
See Also: → CVE-2023-32212
Summary: Datalist option overlap url address bar → Datalist option overlap url address bar after exiting full screen

This doesn't work on Mac: the datalist closes when we exit fullscreen.

The severity field is not set for this bug.
:emilio, could you have a look please?

For more information, please visit BugBot documentation.

Flags: needinfo?(emilio)
Group: layout-core-security → firefox-core-security
Component: Layout: Form Controls → Autocomplete
Flags: needinfo?(emilio)
Product: Core → Toolkit

The severity field is not set for this bug.
:serg, could you have a look please?

For more information, please visit BugBot documentation.

Flags: needinfo?(sgalich)
Severity: -- → S3
Flags: needinfo?(sgalich)
Priority: -- → P3
Duplicate of this bug: 1837581

hello any updates?

hello any updates?

hello any updates?

Assignee: nobody → echen
Status: NEW → ASSIGNED
Duplicate of this bug: 1874615
Pushed by echen@mozilla.com: https://hg.mozilla.org/integration/autoland/rev/a9fd576e6dae Close autocomplete popup when window is resized; r=dimi
Backout by nfay@mozilla.com: https://hg.mozilla.org/integration/autoland/rev/a234c7e39872 Backed out changeset a9fd576e6dae for causing bc failures on browser_window_resize.js CLOSED TREE

Backed out for causing bc failures in browser_window_resize.js
https://hg.mozilla.org/integration/autoland/rev/a234c7e3987289d24292a5058b9edfd79e5b4509

Push with failure
Failure log

TEST-UNEXPECTED-FAIL | toolkit/components/satchel/test/browser/browser_window_resize.js | leaked 1 window(s) until shutdown [url = about:blank]

Flags: needinfo?(echen)
Blocks: 1875630
Duplicate of this bug: 1875630

The severity field for this bug is set to S3. However, the following bug duplicate has higher severity:

:edgar, could you consider increasing the severity of this bug to S2?

For more information, please visit BugBot documentation.

Flags: needinfo?(echen)
Pushed by echen@mozilla.com: https://hg.mozilla.org/integration/autoland/rev/5c3a58685415 Close autocomplete popup when window is resized; r=dimi
Flags: needinfo?(echen)
Group: firefox-core-security → core-security-release
Status: ASSIGNED → RESOLVED
Closed: 1 year ago
Flags: in-testsuite+
Resolution: --- → FIXED
Target Milestone: --- → 124 Branch

The patch landed in nightly and beta is affected.
:edgar, is this bug important enough to require an uplift?

  • If yes, please nominate the patch for beta approval.
  • If no, please set status-firefox123 to wontfix.

For more information, please visit BugBot documentation.

Flags: needinfo?(echen)
Flags: sec-bounty? → sec-bounty+
Keywords: sec-moderatesec-low

This is S3 & sec-low, we probably can let it ride the trains.

Flags: needinfo?(echen)

Backed out for causing test failures on the geckoview bump:
https://hg.mozilla.org/mozilla-central/rev/348b614f401def219f27fea5f374f6e3b822de1c

Status: RESOLVED → REOPENED
Flags: needinfo?(echen)
Resolution: FIXED → ---
Target Milestone: 124 Branch → ---
Backout by pstanciu@mozilla.com: https://hg.mozilla.org/integration/autoland/rev/8261e82577cf Backed out changeset 5c3a58685415 for causing test failures on the GV bump on firefox-android. a=backout CLOSED TREE

There is an r+ patch which didn't land and no activity in this bug for 2 weeks.
:edgar, could you have a look please?
If you still have some work to do, you can add an action "Plan Changes" in Phabricator.
For more information, please visit BugBot documentation.

Flags: needinfo?(echen)
Flags: needinfo?(dlee)

I need to figure out what we can do for GV failures.

Flags: needinfo?(echen)
Flags: needinfo?(dlee)
See Also: → 1890615

This is a general issue of the XUL popup + fullscreen, I will handle this in a more generic way.

Component: Autocomplete → DOM: Core & HTML
Product: Toolkit → Core
Blocks: 1894901
Pushed by echen@mozilla.com: https://hg.mozilla.org/integration/autoland/rev/c1d8b49c933b Close XUL popup when entering/exiting fullscreen; r=smaug
Status: REOPENED → RESOLVED
Closed: 1 year ago1 year ago
Resolution: --- → FIXED
Target Milestone: --- → 127 Branch
No longer duplicate of this bug: 1874615
Attachment #9376918 - Attachment is obsolete: true
Blocks: 1890615
See Also: 1890615
Duplicate of this bug: 1890615
QA Whiteboard: [post-critsmash-triage]
Flags: qe-verify-
Whiteboard: [reporter-external] [client-bounty-form] [verif?] → [reporter-external] [client-bounty-form] [verif?][adv-main127+]
Attached file advisory.txt
Alias: CVE-2024-5698
Group: core-security-release
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Creator:
Created:
Updated:
Size: