Diagcab file extension = Executable files may contain viruses or other malicious code
Categories
(Firefox :: File Handling, defect, P1)
Tracking
()
People
(Reporter: Puf, Assigned: Gijs)
References
Details
(Keywords: reporter-external, sec-moderate, sec-vector, Whiteboard: [adv-main115+][adv-esr102.13+])
Attachments
(5 files, 3 obsolete files)
User Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/113.0.0.0 Safari/537.36 Edg/113.0.1774.42
Steps to reproduce:
Create Diagcab file.
Download In Firefox Browser And Open From Firefox Browser
No " Executable files may contain viruses or other malicious code that could harm your computer "
Actual results:
Diagcab File Comes Under harmful files.
Diagcab file extension Should Be blocklisted to prevent users To Open Directly from Firefox Browser
Diagcab file extension Leads to One-Click Exploits in Windows
This File is Already Blocklisted In Chrome & Edge Browsers
| Reporter | ||
Comment 1•1 year ago
|
||
it's better to Add Popop Warning [ Executable files may contain viruses or other malicious code that could harm your computer]
To Diagcab file To Keep Safe System from Exploits
| Assignee | ||
Updated•1 year ago
|
| Assignee | ||
Updated•1 year ago
|
| Assignee | ||
Comment 3•1 year ago
|
||
| Assignee | ||
Comment 4•1 year ago
|
||
Original Revision: https://phabricator.services.mozilla.com/D181082
| Comment hidden (obsolete) |
Comment 6•1 year ago
|
||
Uplift Approval Request
- Fix verified in Nightly: no
- Risk associated with taking this patch: Low
- Is Android affected?: yes
- Needs manual QE test: yes
- Code covered by automated testing: yes
- User impact if declined: sec-moderate
- String changes made/needed: No
- Steps to reproduce for manual QE testing: Try downloading a diagcab file. If you can't find one easily, rename one in a local file explorer and drag to the tabstrip. Expected behaviour is that once downloaded there's a prompt when trying to open it, rather than it immediately opening a Windows wizard to install something
- Explanation of risk level: just adding an extension to a list
| Assignee | ||
Updated•1 year ago
|
| Assignee | ||
Comment 7•1 year ago
|
||
Note from uplift request on phab, copying for visibility:
The android bits here are a bit confusing - this code is compiled in on Android so in that sense, yes, it's affected. But on the flip side it's not affected by the sec bug... so what does that make of it? I dunno.
Comment 8•1 year ago
|
||
r=mak
https://hg.mozilla.org/integration/autoland/rev/b289ac5d9c2a586f78a29e0b54ec2dae1c132aad
https://hg.mozilla.org/mozilla-central/rev/b289ac5d9c2a
Updated•1 year ago
|
Comment 9•1 year ago
|
||
| uplift | ||
| Reporter | ||
Comment 10•1 year ago
|
||
Hello, For the Bounty, I Have to Email security@mozilla.org?
| Assignee | ||
Comment 11•1 year ago
|
||
(In reply to Puf from comment #10)
Hello, For the Bounty, I Have to Email security@mozilla.org?
I think the bounty flag needs setting, which I've just done for you. Pinging :tjr to check if there's anything else to do.
| Reporter | ||
Comment 12•1 year ago
|
||
Thank You :)
Updated•1 year ago
|
Comment 14•1 year ago
|
||
:mak, since :gijs is on PTO, could you take a look at adding an esr uplift request on this and a patch based on esr?
Comment 15•1 year ago
|
||
Original Revision: https://phabricator.services.mozilla.com/D181082
Comment 16•1 year ago
|
||
Comment on attachment 9340449 [details]
Bug 1837675.
ESR Uplift Approval Request
- If this is not a sec:{high,crit} bug, please state case for ESR consideration: sec-moderate security issue, patched in other browsers
- User impact if declined: diagcab files don't show the executable warning
- Fix Landed on Version: 116
- Risk to taking this patch: Low
- Why is the change risky/not risky? (and alternatives if risky): just adding an extension to a list
Comment 17•1 year ago
|
||
Sorry I tried to insert the request on phabricator but it keeps giving errors.
Comment 18•1 year ago
|
||
Comment on attachment 9340449 [details]
Bug 1837675.
Moving request to esr102
Updated•1 year ago
|
Comment 19•1 year ago
|
||
Reproduced the initial issue using and old Nightly from 2023-06-16, the windows wizard is opened immediately after trying to open the .diagcab files.
Verified that using latest Nightly 2023-06-25 and latest Firefox 115.0b9 Beta version there is a prompt now when trying to open the .diagcab files on both Windows 10 64bit and Windows 11.
Prompt:
"<name>.diagcab is an executable file. Executable files may contain viruses or other malicious code that could harm your computer. Use caution when opening this file. Are you sure you want to launch "<name>.diagcab"?
Removing the qe-verify+ for now, will verify this as well on ESR once/if the fix reaches this branch.
Comment 20•1 year ago
|
||
Comment 21•1 year ago
•
|
||
Comment on attachment 9341131 [details]
Bug 1837675, r=dmeehan
ESR Uplift Approval Request
See comment 16
Updated•1 year ago
|
Updated•1 year ago
|
Updated•1 year ago
|
Updated•1 year ago
|
Updated•1 year ago
|
Comment 22•1 year ago
|
||
Comment 23•1 year ago
|
||
Original Revision: https://phabricator.services.mozilla.com/D182113
Updated•1 year ago
|
Comment 24•1 year ago
•
|
||
Comment on attachment 9341137 [details]
Bug 1837675, r=dmeehan
ESR Uplift Approval Request
see comment 16
This one is on ESR branch. Sorry for the confusion, moz-phab was not doing what I was expecting.
Comment 25•1 year ago
|
||
Comment on attachment 9341137 [details]
Bug 1837675, r=dmeehan
Approved for 102.13esr.
Comment 26•1 year ago
|
||
| uplift | ||
| Reporter | ||
Comment 27•1 year ago
|
||
Please Any Status on Bounty?
Updated•1 year ago
|
Comment 28•1 year ago
|
||
Updated•1 year ago
|
Updated•1 year ago
|
Updated•1 year ago
|
Updated•1 year ago
|
Comment 29•1 year ago
|
||
(In reply to Bogdan Maris, Desktop QA from comment #19)
Reproduced the initial issue using and old Nightly from 2023-06-16, the windows wizard is opened immediately after trying to open the
.diagcabfiles.
Verified that using latest Nightly 2023-06-25 and latest Firefox 115.0b9 Beta version there is a prompt now when trying to open the.diagcabfiles on both Windows 10 64bit and Windows 11.Prompt:
"<name>.diagcab is an executable file. Executable files may contain viruses or other malicious code that could harm your computer. Use caution when opening this file. Are you sure you want to launch "<name>.diagcab"?
Removing the qe-verify+ for now, will verify this as well on ESR once/if the fix reaches this branch.
Also verified that this is fixed on 102.13esr-build2 on the same configurations as above.
Updated•1 year ago
|
Updated•1 year ago
|
Updated•4 months ago
|
Description
•