“ms-cxh” and “ms-cxh-full” protocol handlers considered harmful
Categories
(Firefox :: File Handling, defect)
Tracking
()
People
(Reporter: Gijs, Assigned: Gijs)
References
Details
(Keywords: csectype-dos, sec-low, Whiteboard: [adv-main113+][adv-ESR102.11+])
Attachments
(3 files, 1 obsolete file)
48 bytes,
text/x-phabricator-request
|
RyanVM
:
approval-mozilla-esr102+
|
Details | Review |
48 bytes,
text/x-phabricator-request
|
RyanVM
:
approval-mozilla-beta+
|
Details | Review |
273 bytes,
text/plain
|
Details |
These protocol handlers exist on Win10 and they can do things like soft-locking the machine. They probably shouldn't be accessible through the browser by default.
Assignee | ||
Comment 1•2 years ago
|
||
Updated•2 years ago
|
Comment 2•2 years ago
|
||
r=sclements
https://hg.mozilla.org/integration/autoland/rev/39efb7cf2eb42fb6f8f7e9b601c7ffcc262e81aa
https://hg.mozilla.org/mozilla-central/rev/39efb7cf2eb4
Updated•2 years ago
|
Comment 3•2 years ago
|
||
The patch landed in nightly and beta is affected.
:Gijs, is this bug important enough to require an uplift?
- If yes, please nominate the patch for beta approval.
- If no, please set
status-firefox113
towontfix
.
For more information, please visit auto_nag documentation.
Assignee | ||
Comment 4•2 years ago
|
||
Original Revision: https://phabricator.services.mozilla.com/D175789
Comment 5•2 years ago
|
||
Uplift Approval Request
- Is Android affected?: no
- String changes made/needed: No
- Needs manual QE test: no
- User impact if declined: potential security hole
- Risk associated with taking this patch: Low
- Explanation of risk level: Just adding prefs to block certain protocols in ways we've done numerous times before
- Code covered by automated testing: no
- Fix verified in Nightly: no
- Steps to reproduce for manual QE testing: N/A
Assignee | ||
Updated•2 years ago
|
Updated•2 years ago
|
Comment 6•2 years ago
•
|
||
uplift |
Comment on attachment 9329495 [details]
Bug 1828716, r?sclements
Approved for 113.0b6.
https://hg.mozilla.org/releases/mozilla-beta/rev/e199af712ade1166697d7273a174407ae50d38b7
Comment 7•2 years ago
|
||
Comment on attachment 9329096 [details]
Bug 1828716, r?sclements
Approved for 102.11esr.
Comment 8•2 years ago
|
||
uplift |
Updated•2 years ago
|
Updated•2 years ago
|
Updated•2 years ago
|
Comment 9•2 years ago
|
||
Comment 10•2 years ago
|
||
Updated•2 years ago
|
Updated•1 year ago
|
Description
•