Closed Bug 507938 Opened 16 years ago Closed 16 years ago

XPI whitelist in Firefox can be bypassed by setting homepage of add-on to arbitrary XPI file

Categories

(addons.mozilla.org Graveyard :: Public Pages, defect)

defect
Not set
normal

Tracking

(Not tracked)

VERIFIED DUPLICATE of bug 347759

People

(Reporter: fcp2007, Unassigned)

Details

Maybe this is known, but I am flagging this as security-sensitive just in case. An assumption behind the discussion in bug 425508 comment 6 and later seems to be that currently, an add-on developer cannot link to an arbitrary XPI file from pages in addons.mozilla.org. This assumption is not true. By preparing an arbitrary XPI file on his/her server and setting the homepage (or the support website) of an add-on to that XPI file, an add-on developer can bypass the XPI whitelist in Firefox. This can be thought of as a social kind of security hole. The functionality of linking to an arbitrary URL is not a vulnerability in itself, but it breaks an assumption on which the security of the XPI whitelist in Firefox is based. In my opinion, we have to be clear about what the assumption really is. Note that as Justin says in bug 425508 comment 8, the URL of an XPI file does not necessarily end with .xpi. Even URLs such as http://www.example.com/ can point to an XPI file. We cannot distinguish URLs of XPI files from URLs of the other files. I cannot help claiming that this is not a problem of AMO but it is a problem of Firefox. However, the consensus seems that it is not a problem of Firefox. See bug 425508 comment 10.
Status: NEW → RESOLVED
Closed: 16 years ago
Resolution: --- → DUPLICATE
@Justin: Can you remove the security flag? And thanks for the information!
Group: client-services-security
Verified duplicate. @Justin: Thanks!
Status: RESOLVED → VERIFIED
Product: addons.mozilla.org → addons.mozilla.org Graveyard
You need to log in before you can comment on or make changes to this bug.