Closed Bug 1885855 (CVE-2024-3863) Opened 9 months ago Closed 9 months ago

Treat xrm-ms files as executable (so we warn about them)

Categories

(Toolkit :: Downloads API, defect, P3)

Desktop
Windows
defect

Tracking

()

VERIFIED FIXED
126 Branch
Tracking Status
firefox-esr115 125+ verified
firefox124 --- wontfix
firefox125 + verified
firefox126 + verified

People

(Reporter: Gijs, Assigned: mak)

Details

(Keywords: sec-moderate, sec-vector, Whiteboard: [adv-main125+][adv-esr115.10+])

Attachments

(4 files)

No description provided.
Assignee: nobody → mak
Attached file Bug 1885855. r=dimi

Daniel, I assume dependencies of a bug inherit its sec level, so this would also be sec-moderate. Though as I don't want to bend rules, I'm asking for confirmation.

Flags: needinfo?(dveditz)

Sometimes. we have to balance the fact that this is a separate bug in its own right with not wanting to double-count issues and getting teams in trouble for "having too many security bugs". In this case, sec-moderate seem good.

Flags: needinfo?(dveditz)
Keywords: sec-moderate
Group: firefox-core-security → core-security-release
Status: NEW → RESOLVED
Closed: 9 months ago
Resolution: --- → FIXED
Target Milestone: --- → 126 Branch

:mak does this impact ESR115 wondering if we need an uplift there also?

Flags: needinfo?(mak)

Yes, I'll start asking for uplifts.

Flags: needinfo?(mak)
Attachment #9392778 - Flags: approval-mozilla-beta?

Uplift Approval Request

  • Explanation of risk level: Adding file extension to a list
  • User impact if declined: sec-moderate risk on opening the file
  • Is Android affected?: no
  • Code covered by automated testing: yes
  • Needs manual QE test: yes
  • String changes made/needed: No
  • Fix verified in Nightly: no
  • Risk associated with taking this patch: Low
  • Steps to reproduce for manual QE testing: Try downloading a file with one of these extensions. If you can't find one easily, rename one in a local file explorer and drag to the tabstrip. Expected behaviour is that once downloaded there's a prompt when trying to open it, rather than it immediately opening
Flags: qe-verify+
Attachment #9392787 - Flags: approval-mozilla-esr115?

Uplift Approval Request

  • User impact if declined: sec-moderate risk on opening the file
  • Is Android affected?: no
  • Code covered by automated testing: yes
  • Explanation of risk level: Adding file extension to a list
  • Risk associated with taking this patch: Low
  • Fix verified in Nightly: no
  • Steps to reproduce for manual QE testing: yes
  • Needs manual QE test: yes
  • String changes made/needed: No
OS: All → Windows
Attachment #9392778 - Flags: approval-mozilla-beta? → approval-mozilla-beta+
Attachment #9392787 - Flags: approval-mozilla-esr115? → approval-mozilla-esr115+
QA Whiteboard: [post-critsmash-triage]
QA Whiteboard: [post-critsmash-triage] → [post-critsmash-triage][qa-triaged]

I've reproduced this issue on Win 11 x64 with an affected Nightly build, 2024-03-18. Thank you, Marco for providing the test file.

The issue is verified as fixed on Win 11 x64 using the latest builds, Nightly 126.0a1, Beta 125.0b4 and Esr 115.10.0.

Status: RESOLVED → VERIFIED
Flags: qe-verify+
Whiteboard: [adv-main125+][adv-esr115.10+]
Attached file advisory.txt
Keywords: sec-vector
Alias: CVE-2024-3863
Group: core-security-release
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: