Remote content loading is wrongly allowed for encrypted messages when loaded from a file
Categories
(MailNews Core :: Security: OpenPGP, defect, P2)
Tracking
(thunderbird_esr140 wontfix, thunderbird_esr153 affected)
People
(Reporter: KaiE, Assigned: KaiE)
References
(Blocks 1 open bug)
Details
(Whiteboard: [mailsec-vuln-fixwanted])
Attachments
(2 files, 2 obsolete files)
While working on bug 1994709 I discovered that we're not completely blocking the load of remote content in encrypted messages.
When saving an encrypted message to a file, and then using file open to display the message, we will allow remote content loading (the remote content warning banner will allow overriding).
That problem applies for both S/MIME and OpenPGP messages.
It seems I have a fix in hand and will attach tomorrow.
| Assignee | ||
Updated•3 months ago
|
| Assignee | ||
Updated•3 months ago
|
| Assignee | ||
Comment 1•3 months ago
|
||
Note that it works as intended when a message is loaded from a folder. The fix from bug 1925929 works correctly in that scenario.
| Assignee | ||
Comment 2•3 months ago
|
||
The issue is that nsIEncryptedSMIMEURIsService isn't working sufficiently in all scenarios.
The code in msgHdrViewSMIMEOverlay.js and enigmailMsgHdrViewOverlay already registers two different URI presentations, but that's still different from what nsMsgContentPolicy::ShouldLoad uses ( aRequestingLocation->GetSpecOrDefault() ).
I think we should change nsIEncryptedSMIMEURIsService to use a canonical message ID.
We could do so by porting msgIdentificationFromUrl to C++.
| Assignee | ||
Comment 3•3 months ago
|
||
(In reply to Kai Engert [:KaiE:] from comment #2)
I think we should change nsIEncryptedSMIMEURIsService to use a canonical message ID.
We could do so by porting msgIdentificationFromUrl to C++.
This wouldn't cover necko/display URIs.
It's still easier to register twice, so the service doesn't need additional dependencies.
| Assignee | ||
Comment 4•3 months ago
|
||
| Assignee | ||
Comment 5•3 months ago
|
||
| Assignee | ||
Comment 6•3 months ago
|
||
The patch from comment 5 - https://phabricator.services.mozilla.com/D310222 - actually belongs to bug 1994709 - but it overlaps with the work from this bug here.
I don't want to expose this security sensitive bug yet, so I'm temporarily tracking that other patch in this bug (until this bug has been resolved).
Comment 7•3 months ago
|
||
I've set version to the current esr. Please adjust version if this is only a newer issue.
| Assignee | ||
Comment 8•3 months ago
|
||
(In reply to Wayne Mery (:wsmwk) from comment #7)
I've set version to the current esr. Please adjust version if this is only a newer issue.
it's much older.
| Assignee | ||
Comment 9•2 months ago
|
||
I would like to unhide this bug.
I need to get it commited as a base patch for 1994709.
And while I think it should be backported to ESR, it's not clear whether it will.
The scenario is rather unusual.
And even if a user saves a message to a file and opens it from there, we still get the remote content blocking by default.
| Assignee | ||
Comment 10•2 months ago
|
||
Updated•2 months ago
|
Updated•2 months ago
|
| Assignee | ||
Updated•2 months ago
|
| Assignee | ||
Updated•2 months ago
|
Updated•1 month ago
|
| Assignee | ||
Updated•1 month ago
|
| Assignee | ||
Updated•1 month ago
|
| Assignee | ||
Updated•1 month ago
|
Updated•1 month ago
|
Comment 11•1 month ago
|
||
Pushed by brendan@thunderbird.net:
https://hg.mozilla.org/comm-central/rev/c9d1fb051c45
Improve correctness of nsIEncryptedSMIMEURIsService lookups. r=mkmelin
| Assignee | ||
Comment 12•1 month ago
|
||
Reopening, because a follow-up patch is necessary to fix windows-only permanent test failure.
TEST-UNEXPECTED-FAIL | comm/mailnews/extensions/smime/test/unit/test_encryptedURIsService.js | test_differentQueryRepresentationsMatch - [test_differentQueryRepresentationsMatch : 28] the display URL must match the registered necko URL for the same message - false == true
| Assignee | ||
Comment 13•1 month ago
|
||
Updated•1 month ago
|
| Assignee | ||
Updated•1 month ago
|
Comment 14•1 month ago
|
||
Pushed by brendan@thunderbird.net:
https://hg.mozilla.org/comm-central/rev/e52718bc5b79
Follow-up to fix Windows-only test failure. r=mkmelin
Description
•