Diagcab file extension = Executable files may contain viruses or other malicious code
Categories
(Firefox :: File Handling, defect, P1)
Tracking
()
People
(Reporter: Puf, Assigned: Gijs)
References
Details
(Keywords: reporter-external, sec-moderate, sec-vector, Whiteboard: [adv-main115+][adv-esr102.13+])
Attachments
(5 files, 3 obsolete files)
User Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/113.0.0.0 Safari/537.36 Edg/113.0.1774.42
Steps to reproduce:
Create Diagcab file.
Download In Firefox Browser And Open From Firefox Browser
No " Executable files may contain viruses or other malicious code that could harm your computer "
Actual results:
Diagcab File Comes Under harmful files.
Diagcab file extension Should Be blocklisted to prevent users To Open Directly from Firefox Browser
Diagcab file extension Leads to One-Click Exploits in Windows
This File is Already Blocklisted In Chrome & Edge Browsers
Reporter | ||
Comment 1•2 years ago
|
||
it's better to Add Popop Warning [ Executable files may contain viruses or other malicious code that could harm your computer]
To Diagcab file To Keep Safe System from Exploits
Assignee | ||
Updated•2 years ago
|
Assignee | ||
Updated•2 years ago
|
Assignee | ||
Comment 3•2 years ago
|
||
Assignee | ||
Comment 4•2 years ago
|
||
Original Revision: https://phabricator.services.mozilla.com/D181082
Comment hidden (obsolete) |
Comment 6•2 years ago
|
||
Uplift Approval Request
- Fix verified in Nightly: no
- Risk associated with taking this patch: Low
- Is Android affected?: yes
- Needs manual QE test: yes
- Code covered by automated testing: yes
- User impact if declined: sec-moderate
- String changes made/needed: No
- Steps to reproduce for manual QE testing: Try downloading a diagcab file. If you can't find one easily, rename one in a local file explorer and drag to the tabstrip. Expected behaviour is that once downloaded there's a prompt when trying to open it, rather than it immediately opening a Windows wizard to install something
- Explanation of risk level: just adding an extension to a list
Assignee | ||
Updated•2 years ago
|
Assignee | ||
Comment 7•2 years ago
|
||
Note from uplift request on phab, copying for visibility:
The android bits here are a bit confusing - this code is compiled in on Android so in that sense, yes, it's affected. But on the flip side it's not affected by the sec bug... so what does that make of it? I dunno.
![]() |
||
Comment 8•2 years ago
|
||
r=mak
https://hg.mozilla.org/integration/autoland/rev/b289ac5d9c2a586f78a29e0b54ec2dae1c132aad
https://hg.mozilla.org/mozilla-central/rev/b289ac5d9c2a
Updated•2 years ago
|
Comment 9•2 years ago
|
||
uplift |
Reporter | ||
Comment 10•2 years ago
|
||
Hello, For the Bounty, I Have to Email security@mozilla.org?
Assignee | ||
Comment 11•2 years ago
|
||
(In reply to Puf from comment #10)
Hello, For the Bounty, I Have to Email security@mozilla.org?
I think the bounty flag needs setting, which I've just done for you. Pinging :tjr to check if there's anything else to do.
Reporter | ||
Comment 12•2 years ago
|
||
Thank You :)
Updated•2 years ago
|
Comment 14•2 years ago
|
||
:mak, since :gijs is on PTO, could you take a look at adding an esr uplift request on this and a patch based on esr?
Comment 15•2 years ago
|
||
Original Revision: https://phabricator.services.mozilla.com/D181082
Comment 16•2 years ago
|
||
Comment on attachment 9340449 [details]
Bug 1837675.
ESR Uplift Approval Request
- If this is not a sec:{high,crit} bug, please state case for ESR consideration: sec-moderate security issue, patched in other browsers
- User impact if declined: diagcab files don't show the executable warning
- Fix Landed on Version: 116
- Risk to taking this patch: Low
- Why is the change risky/not risky? (and alternatives if risky): just adding an extension to a list
Comment 17•2 years ago
|
||
Sorry I tried to insert the request on phabricator but it keeps giving errors.
Comment 18•2 years ago
|
||
Comment on attachment 9340449 [details]
Bug 1837675.
Moving request to esr102
Updated•2 years ago
|
Comment 19•2 years ago
|
||
Reproduced the initial issue using and old Nightly from 2023-06-16, the windows wizard is opened immediately after trying to open the .diagcab
files.
Verified that using latest Nightly 2023-06-25 and latest Firefox 115.0b9 Beta version there is a prompt now when trying to open the .diagcab
files on both Windows 10 64bit and Windows 11.
Prompt:
"<name>.diagcab is an executable file. Executable files may contain viruses or other malicious code that could harm your computer. Use caution when opening this file. Are you sure you want to launch "<name>.diagcab"?
Removing the qe-verify+ for now, will verify this as well on ESR once/if the fix reaches this branch.
Comment 20•2 years ago
|
||
Comment 21•2 years ago
•
|
||
Comment on attachment 9341131 [details]
Bug 1837675, r=dmeehan
ESR Uplift Approval Request
See comment 16
Updated•2 years ago
|
Updated•2 years ago
|
Updated•2 years ago
|
Updated•2 years ago
|
Updated•2 years ago
|
Comment 22•2 years ago
|
||
Comment 23•2 years ago
|
||
Original Revision: https://phabricator.services.mozilla.com/D182113
Updated•2 years ago
|
Comment 24•2 years ago
•
|
||
Comment on attachment 9341137 [details]
Bug 1837675, r=dmeehan
ESR Uplift Approval Request
see comment 16
This one is on ESR branch. Sorry for the confusion, moz-phab was not doing what I was expecting.
Comment 25•2 years ago
|
||
Comment on attachment 9341137 [details]
Bug 1837675, r=dmeehan
Approved for 102.13esr.
Comment 26•2 years ago
|
||
uplift |
Reporter | ||
Comment 27•2 years ago
|
||
Please Any Status on Bounty?
Updated•2 years ago
|
Comment 28•2 years ago
|
||
Updated•2 years ago
|
Updated•2 years ago
|
Updated•2 years ago
|
Updated•2 years ago
|
Comment 29•2 years ago
|
||
(In reply to Bogdan Maris, Desktop QA from comment #19)
Reproduced the initial issue using and old Nightly from 2023-06-16, the windows wizard is opened immediately after trying to open the
.diagcab
files.
Verified that using latest Nightly 2023-06-25 and latest Firefox 115.0b9 Beta version there is a prompt now when trying to open the.diagcab
files on both Windows 10 64bit and Windows 11.Prompt:
"<name>.diagcab is an executable file. Executable files may contain viruses or other malicious code that could harm your computer. Use caution when opening this file. Are you sure you want to launch "<name>.diagcab"?
Removing the qe-verify+ for now, will verify this as well on ESR once/if the fix reaches this branch.
Also verified that this is fixed on 102.13esr-build2 on the same configurations as above.
Updated•2 years ago
|
Updated•2 years ago
|
Updated•1 year ago
|
Description
•