Firefox browser incorrectly parsed the subject key identifier of the digital certificate.
Categories
(Firefox :: Security, defect, P3)
Tracking
()
People
(Reporter: 2295456556, Unassigned)
References
(Blocks 2 open bugs)
Details
Attachments
(4 files)
User Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36 Edg/119.0.0.0
Steps to reproduce:
1.Mutating a certificate.
2.Running the browser to parse the mutated certificate file.
3.Observing the results.
Actual results:
We mutated the node that represents the specific information of the user key identifier in the certificate. Chrome does not recognize this incorrect structure and displays that it cannot parse. However, Firefox simply parses and displays the sibling node of the OID node that represents the user key identifier as the node that represents the specific information of the user key identifier.
Expected results:
Firefox should recognize this incorrect structure and display a parsing error or other message
| Reporter | ||
Comment 1•2 years ago
|
||
| Reporter | ||
Comment 2•2 years ago
|
||
| Reporter | ||
Updated•2 years ago
|
| Reporter | ||
Updated•2 years ago
|
| Reporter | ||
Comment 3•2 years ago
|
||
Comment 4•2 years ago
|
||
The Bugbug bot thinks this bug should belong to the 'Firefox::Security' component, and is moving the bug to that component. Please correct in case you think the bot is wrong.
Updated•2 years ago
|
Comment 5•2 years ago
|
||
The severity field is not set for this bug.
:serg, could you have a look please?
For more information, please visit BugBot documentation.
Comment 6•1 year ago
|
||
Redirect a needinfo that is pending on an inactive user to the triage owner.
:manuel, since the bug doesn't have a severity set, could you please set the severity or close the bug?
For more information, please visit BugBot documentation.
Comment 7•1 year ago
|
||
Waiting for response on https://github.com/PeculiarVentures/PKI.js/issues/425
Updated•1 year ago
|
Updated•1 year ago
|
Description
•