firefox 63.0 out of bounds read/or wrong firewall rule

Bug #1804486 reported by Jan Hafer
256
This bug affects 1 person
Affects Status Importance Assigned to Milestone
firefox (Ubuntu)
Expired
Undecided
Unassigned

Bug Description

On using the application knime the download was intercepted by firewall rules of the university network with the following error:
File-Text_Mozilla-Firefox-HTTP-Index-Format-File-Out-Of-Bounds-Read

This may be associated by
https://www.mozilla.org/en-US/security/advisories/mfsa2017-10/#CVE-2017-5446

Was the mitigation ported/used in firefox 63.0 ?
Are security updates for common used programs (firefox 63.3 is current version) not supported on LTS anymore?

CVE References

information type: Private Security → Public Security
Changed in firefox (Ubuntu):
status: New → Incomplete
Revision history for this message
Seth Arnold (seth-arnold) wrote :

Hello Jan, there's too little information here to really say what's going on.

I don't know what your university's firewall rules are telling us.

It's certainly possible that Firefox's fix for CVE-2017-5446 has regressed in the last year and a half, but without further evidence that this is infact related to what your firewall system is trying to tell us, it's probably best to not go down this route too far.

Can you test other browsers? Can you capture the network traffic?

Thanks

Revision history for this message
Jan Hafer (matu3ba) wrote :

I got the reply that the signature relates to a CVE from 2017,
in this case CBE-2017-5444
[I guess that is a spelling error meaning CVE-2017-5444]

More precise notes to the signature they do not have.
They suspected it has no more relevance, so they deactivated it (after my request).

Shall I ask them to give me the rule affected?
I am currently in the process of getting information from the other affected persons.

Revision history for this message
Launchpad Janitor (janitor) wrote :

[Expired for firefox (Ubuntu) because there has been no activity for 60 days.]

Changed in firefox (Ubuntu):
status: Incomplete → Expired
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.