backport m-c 1435319: CVE-2018-12381 - Dropping an Outlook email message into the browser window will trigger a page navigation when the message's mail columns are incorrectly interpreted as a URL.

This commit is contained in:
Gaming4JC 2018-10-09 17:35:00 -04:00 • committed by Roy Tam
commit d6206801dd
2 changed files with 29 additions and 8 deletions

View file

@ -154,6 +154,15 @@ HasUserPassword(const nsACString& aStringURI)
return false; return false;
} }
// Assume that 1 tab is accidental, but more than 1 implies this is
// supposed to be tab-separated content.
static bool
MaybeTabSeparatedContent(const nsCString& aStringURI)
{
auto firstTab = aStringURI.FindChar('\t');
return firstTab != kNotFound && aStringURI.RFindChar('\t') != firstTab;
}
NS_IMETHODIMP NS_IMETHODIMP
nsDefaultURIFixup::GetFixupURIInfo(const nsACString& aStringURI, nsDefaultURIFixup::GetFixupURIInfo(const nsACString& aStringURI,
uint32_t aFixupFlags, uint32_t aFixupFlags,
@ -168,8 +177,8 @@ nsDefaultURIFixup::GetFixupURIInfo(const nsACString& aStringURI,
// Eliminate embedded newlines, which single-line text fields now allow: // Eliminate embedded newlines, which single-line text fields now allow:
uriString.StripChars("\r\n"); uriString.StripChars("\r\n");
// Cleanup the empty spaces that might be on each end: // Cleanup the empty spaces and tabs that might be on each end:
uriString.Trim(" "); uriString.Trim(" \t");
NS_ENSURE_TRUE(!uriString.IsEmpty(), NS_ERROR_FAILURE); NS_ENSURE_TRUE(!uriString.IsEmpty(), NS_ERROR_FAILURE);
@ -367,12 +376,16 @@ nsDefaultURIFixup::GetFixupURIInfo(const nsACString& aStringURI,
inputHadDuffProtocol = true; inputHadDuffProtocol = true;
} }
// NB: this rv gets returned at the end of this method if we never // Note: this rv gets returned at the end of this method if we don't fix up
// do a keyword fixup after this (because the pref or the flags passed // the protocol and don't do a keyword fixup after this (because the pref
// might not let us). // or the flags passed might not let us).
rv = FixupURIProtocol(uriString, info, getter_AddRefs(uriWithProtocol)); rv = NS_OK;
if (uriWithProtocol) { // Avoid fixing up content that looks like tab-separated values
info->mFixedURI = uriWithProtocol; if (!MaybeTabSeparatedContent(uriString)) {
rv = FixupURIProtocol(uriString, info, getter_AddRefs(uriWithProtocol));
if (uriWithProtocol) {
info->mFixedURI = uriWithProtocol;
}
} }
// See if it is a keyword // See if it is a keyword

View file

@ -469,6 +469,14 @@ var testcases = [ {
keywordLookup: true, keywordLookup: true,
protocolChange: true, protocolChange: true,
affectedByDNSForSingleHosts: true, affectedByDNSForSingleHosts: true,
}, {
input: " \t mozilla.org/\t \t ",
fixedURI: "http://mozilla.org/",
alternateURI: "http://www.mozilla.org/",
protocolChange: true,
}, {
input: " moz\ti\tlla.org ",
keywordLookup: true,
}]; }];
if (Services.appinfo.OS.toLowerCase().startsWith("win")) { if (Services.appinfo.OS.toLowerCase().startsWith("win")) {