Treat xrm-ms files as executable (so we warn about them)
Categories
(Toolkit :: Downloads API, defect, P3)
Tracking
()
People
(Reporter: Gijs, Assigned: mak)
Details
(Keywords: sec-moderate, sec-vector, Whiteboard: [adv-main125+][adv-esr115.10+])
Attachments
(4 files)
48 bytes,
text/x-phabricator-request
|
Details | Review | |
48 bytes,
text/x-phabricator-request
|
phab-bot
:
approval-mozilla-beta+
|
Details | Review |
48 bytes,
text/x-phabricator-request
|
phab-bot
:
approval-mozilla-esr115+
|
Details | Review |
316 bytes,
text/plain
|
Details |
Reporter | ||
Updated•2 years ago
|
Assignee | ||
Comment 1•2 years ago
|
||
Assignee | ||
Comment 2•2 years ago
|
||
Daniel, I assume dependencies of a bug inherit its sec level, so this would also be sec-moderate. Though as I don't want to bend rules, I'm asking for confirmation.
Comment 3•2 years ago
|
||
Sometimes. we have to balance the fact that this is a separate bug in its own right with not wanting to double-count issues and getting teams in trouble for "having too many security bugs". In this case, sec-moderate seem good.
![]() |
||
Comment 5•2 years ago
|
||
Comment 6•2 years ago
•
|
||
:mak does this impact ESR115 wondering if we need an uplift there also?
Updated•2 years ago
|
Assignee | ||
Comment 8•2 years ago
|
||
Original Revision: https://phabricator.services.mozilla.com/D205067
Updated•2 years ago
|
Comment 9•2 years ago
|
||
Uplift Approval Request
- Explanation of risk level: Adding file extension to a list
- User impact if declined: sec-moderate risk on opening the file
- Is Android affected?: no
- Code covered by automated testing: yes
- Needs manual QE test: yes
- String changes made/needed: No
- Fix verified in Nightly: no
- Risk associated with taking this patch: Low
- Steps to reproduce for manual QE testing: Try downloading a file with one of these extensions. If you can't find one easily, rename one in a local file explorer and drag to the tabstrip. Expected behaviour is that once downloaded there's a prompt when trying to open it, rather than it immediately opening
Assignee | ||
Comment 10•2 years ago
|
||
Original Revision: https://phabricator.services.mozilla.com/D205067
Updated•2 years ago
|
Comment 11•2 years ago
|
||
Uplift Approval Request
- User impact if declined: sec-moderate risk on opening the file
- Is Android affected?: no
- Code covered by automated testing: yes
- Explanation of risk level: Adding file extension to a list
- Risk associated with taking this patch: Low
- Fix verified in Nightly: no
- Steps to reproduce for manual QE testing: yes
- Needs manual QE test: yes
- String changes made/needed: No
Assignee | ||
Updated•2 years ago
|
Updated•2 years ago
|
Updated•2 years ago
|
Updated•2 years ago
|
Updated•2 years ago
|
Comment 12•2 years ago
|
||
uplift |
Comment 13•2 years ago
|
||
uplift |
Updated•2 years ago
|
Updated•2 years ago
|
Comment 14•2 years ago
|
||
I've reproduced this issue on Win 11 x64 with an affected Nightly build, 2024-03-18. Thank you, Marco for providing the test file.
The issue is verified as fixed on Win 11 x64 using the latest builds, Nightly 126.0a1, Beta 125.0b4 and Esr 115.10.0.
Updated•2 years ago
|
Comment 15•2 years ago
|
||
Updated•2 years ago
|
Updated•2 years ago
|
Updated•1 year ago
|
Description
•