Drag-and-Drop and File Extension Bugs Enable Dropping of Malicious File
Categories
(Core :: DOM: Copy & Paste and Drag & Drop, defect)
Tracking
()
People
(Reporter: curtisk, Assigned: enndeakin)
References
Details
(Keywords: csectype-other, sec-moderate, Whiteboard: Disclosure planned by EOY 2013, Chrome bug public now [adv-main102+])
Attachments
(2 files, 1 obsolete file)
Assignee | ||
Comment 1•12 years ago
|
||
Comment 2•12 years ago
|
||
Updated•12 years ago
|
Updated•12 years ago
|
Updated•12 years ago
|
Updated•12 years ago
|
Updated•11 years ago
|
Updated•9 years ago
|
Assignee | ||
Comment 3•3 years ago
|
||
Any remaining issues should have been fixed by 1746052.
Updated•3 years ago
|
Updated•3 years ago
|
Updated•3 years ago
|
Comment 4•3 years ago
|
||
Comment 5•3 years ago
|
||
Not sure if the info from comment 2 is still relevant being 9 years old. Drag and drop action on the file in question is blocked in the fixed version (tested with Fx 102, on Windows 10). Is this the expected behavior? If not, can you provide some applicable steps to be able to confirm the fix. Thank you!
Comment 6•3 years ago
|
||
Updated•3 years ago
|
Comment 7•3 years ago
|
||
Assignee | ||
Comment 8•3 years ago
|
||
I'm not sure that the testcase is relevant anymore. I assume at some point in the past, one could drag invalid images. The tests in the linked chrome bug also work fine.
Comment 9•2 years ago
|
||
(In reply to Neil Deakin from comment #8)
I'm not sure that the testcase is relevant anymore. I assume at some point in the past, one could drag invalid images. The tests in the linked chrome bug also work fine.
Thank you for your response. I will remove the qe+ from the bug in this case.
Updated•2 years ago
|
Description
•