Closed Bug 40756 Opened 26 years ago Closed 24 years ago

MailNews needs security review to avoid mail bombs etc.

Categories

(MailNews Core :: Security, defect, P3)

defect

Tracking

(Not tracked)

VERIFIED FIXED
mozilla1.0

People

(Reporter: selmer, Assigned: security-bugs)

References

Details

(Keywords: meta)

Mitch, we have a line item in our PRD that we're supposed to be safe from all possible mail attacks. Can you help us coordinate some kind of review that would help provide assurances that we're safe? Thanks, Steve
We should make sure we're safe before we ship beta2, adding keyword.
Severity: trivial → critical
Keywords: nsbeta2
Hardware: PC → Sun
Target Milestone: --- → M17
Sure. Why don't you set up a meeting of interested parties and we can think about how to tackle this. We should try to find a list of past security exploits involving mail and see if we're still vulnerable - maybe there's some in bugsplat?
Status: NEW → ASSIGNED
Putting on [nsbeta2-] radar. This is a "meeting" tracking bug. Sooo, have your mtg to see if there is a bug...but this bug is minus baby!
Whiteboard: [nsbeta2-]
adding alecf, mscott, bienvenu and me to this bug. when we get to talking about security in mailnews, I'm sure we'll all want to be there. the last I heard (from mscott) was there was a bug that prevented any JS from being executed in the message pane. the message pane is still in it's own iframe, so does that mean if that bug gets fixed, will we be safe?
Assigning QA to czhang
QA Contact: lchiang → czhang
Has there been any followup to last month's mailnews security meeting? Major issues still unresolved? Let's make this a meta-bug for mailnews security issues. Here are my notes from the meeting: General consensus that - Make sure scripts in the message pane don't have access to the message header. (me) - Each mail message should be its own sandbox; no access to other messages or pages (me) - Disabling JS in mail/news. This is now the default in Mozilla, not NS6. (done) - Are there any circumstances where the "URL" of two messages is the same? This would allow one to access the other. (me) - Disabling the covert channel caused by network requests initiated by the display of a message (the infamous bug 28327, let's continue discussion in that bug) - The setting of a cookie by script in a message ties a cookie to an email address, which can be a privacy violation. Should this be fixed? Worth opening a bug? - Do we remove the hack that allowed HTML in vcards? - As I write this, mscott has brought bug 48403 to my attention, a nice little exploit which can be run from a mail message.
Depends on: ImgInMail, 48403
Keywords: nsbeta2meta
Whiteboard: [nsbeta2-]
Good bug! > The setting of a cookie by script in a message ties a cookie to an email > address, which can be a privacy violation. Should this be fixed? Worth opening > a bug? Can you tell more about this?
> Make sure scripts in the message pane don't have access to the message header You mean the header section of the msg pane? (Because there are "save/open attachment" functions available, which a script might be able to invoke, not?)
I believe there is already a bug around somewhere for the cookie-in-email issue
I think, you mean bug 22994.
Depends on: 22994
Additional security reviews will take place after PR3, marking rtm.
Keywords: rtm
Blocks: 26603
Has this review begun? Is there an eta? Adding Need Info.
Whiteboard: [need info]
QA Contact: czhang → paw
Ongoing. I've looked at some mail issues with mscott lately; I'd like to have another meeting soon.
PDT marking [rtm-] on this to-do item.
Whiteboard: [need info] → [rtm-]
UPdated QA Contact
QA Contact: paw → ckritzer
Target Milestone: M17 → ---
Mass adding mozilla0.9 keyword (mass changing milestone doesn't seem to work).
Keywords: mozilla0.9
As Mozilla 0.9 and the final 1.0 release is getting nearer, I suggest you schedule this meeting soon. It is very important that the majority of these bugs gets fixed before 1.0
OS: Windows NT → All
Hardware: Sun → All
Target Milestone: --- → mozilla1.0
Bugs targeted at mozilla1.0 without the mozilla1.0 keyword moved to mozilla1.0.1 (you can query for this string to delete spam or retrieve the list of bugs I've moved)
Target Milestone: mozilla1.0 → mozilla1.0.1
Resetting Milestone (due to mass-change) and adding mozilla 1.0 keyword.
Keywords: nsrtmmozilla1.0
Whiteboard: [rtm-]
Target Milestone: mozilla1.0.1 → ---
Target Milestone: --- → mozilla1.0
OK, this review is underway and is being tracked elsewhere, so I'm going to close this bug. If you'd like to help with this effort, take a look at http://www.mozilla.org/projects/security/components/reviewguide.html or email mstoltz@netscape.com with your suggestions.
Status: ASSIGNED → RESOLVED
Closed: 24 years ago
Resolution: --- → FIXED
> this review is underway and is being tracked elsewhere Where is tracked? > http://www.mozilla.org/projects/security/components/reviewguide.html Thanks for the URL/doc, good read.
Marking verified as per above developer comments. The QA team is also involved in this initiative. Please contact bsharma@netscpae.com if you have any testing issues or want to help in the testing area.
Status: RESOLVED → VERIFIED
Product: MailNews → Core
Product: Core → MailNews Core
You need to log in before you can comment on or make changes to this bug.