Closed Bug 2052070 Opened 3 months ago Closed 1 month ago

Remote content loading is wrongly allowed for encrypted messages when loaded from a file

Categories

(MailNews Core :: Security: OpenPGP, defect, P2)

Thunderbird 140
defect

Tracking

(thunderbird_esr140 wontfix, thunderbird_esr153 affected)

RESOLVED FIXED
156 Branch
Tracking Status
thunderbird_esr140 --- wontfix
thunderbird_esr153 --- affected

People

(Reporter: KaiE, Assigned: KaiE)

References

(Blocks 1 open bug)

Details

(Whiteboard: [mailsec-vuln-fixwanted])

Attachments

(2 files, 2 obsolete files)

While working on bug 1994709 I discovered that we're not completely blocking the load of remote content in encrypted messages.

When saving an encrypted message to a file, and then using file open to display the message, we will allow remote content loading (the remote content warning banner will allow overriding).

That problem applies for both S/MIME and OpenPGP messages.

It seems I have a fix in hand and will attach tomorrow.

Depends on: 2052219, 2052244
See Also: → CVE-2024-11159

Note that it works as intended when a message is loaded from a folder. The fix from bug 1925929 works correctly in that scenario.

The issue is that nsIEncryptedSMIMEURIsService isn't working sufficiently in all scenarios.

The code in msgHdrViewSMIMEOverlay.js and enigmailMsgHdrViewOverlay already registers two different URI presentations, but that's still different from what nsMsgContentPolicy::ShouldLoad uses ( aRequestingLocation->GetSpecOrDefault() ).

I think we should change nsIEncryptedSMIMEURIsService to use a canonical message ID.
We could do so by porting msgIdentificationFromUrl to C++.

(In reply to Kai Engert [:KaiE:] from comment #2)

I think we should change nsIEncryptedSMIMEURIsService to use a canonical message ID.
We could do so by porting msgIdentificationFromUrl to C++.

This wouldn't cover necko/display URIs.
It's still easier to register twice, so the service doesn't need additional dependencies.

The patch from comment 5 - https://phabricator.services.mozilla.com/D310222 - actually belongs to bug 1994709 - but it overlaps with the work from this bug here.

I don't want to expose this security sensitive bug yet, so I'm temporarily tracking that other patch in this bug (until this bug has been resolved).

I've set version to the current esr. Please adjust version if this is only a newer issue.

Version: unspecified → Thunderbird 140

(In reply to Wayne Mery (:wsmwk) from comment #7)

I've set version to the current esr. Please adjust version if this is only a newer issue.

it's much older.

I would like to unhide this bug.

I need to get it commited as a base patch for 1994709.
And while I think it should be backported to ESR, it's not clear whether it will.

The scenario is rather unusual.
And even if a user saves a message to a file and opens it from there, we still get the remote content blocking by default.

Group: mail-core-security
Attachment #9604049 - Attachment description: (secure) → WIP: Bug 2052070 - Improve correctness of nsIEncryptedSMIMEURIsService lookups.
Attachment #9604049 - Attachment is obsolete: true
Attachment #9604080 - Attachment description: (secure) → WIP: Bug 2052070 - Allow remote content for integrity-protected OpenPGP messages.
Attachment #9604080 - Attachment is obsolete: true
Blocks: 1994709
Depends on: 2052069
Whiteboard: [mailsec-vuln-fixwanted]
Severity: -- → S2
Priority: -- → P2
Attachment #9604993 - Attachment description: WIP: Bug 2052070 - Improve correctness of nsIEncryptedSMIMEURIsService lookups. → Bug 2052070 - Improve correctness of nsIEncryptedSMIMEURIsService lookups. r=mkmelin
Target Milestone: --- → 156 Branch

Pushed by brendan@thunderbird.net:
https://hg.mozilla.org/comm-central/rev/c9d1fb051c45
Improve correctness of nsIEncryptedSMIMEURIsService lookups. r=mkmelin

Status: NEW → RESOLVED
Closed: 1 month ago
Resolution: --- → FIXED

Reopening, because a follow-up patch is necessary to fix windows-only permanent test failure.
TEST-UNEXPECTED-FAIL | comm/mailnews/extensions/smime/test/unit/test_encryptedURIsService.js | test_differentQueryRepresentationsMatch - [test_differentQueryRepresentationsMatch : 28] the display URL must match the registered necko URL for the same message - false == true

Status: RESOLVED → REOPENED
Resolution: FIXED → ---
Attachment #9631390 - Attachment description: WIP: Bug 2052070 - Follow-up to fix Windows-only test failure. → Bug 2052070 - Follow-up to fix Windows-only test failure. r=mkmelin

Pushed by brendan@thunderbird.net:
https://hg.mozilla.org/comm-central/rev/e52718bc5b79
Follow-up to fix Windows-only test failure. r=mkmelin

Status: REOPENED → RESOLVED
Closed: 1 month ago → 1 month ago
Resolution: --- → FIXED
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: