Security/Fileabug: Difference between revisions

Line 9: Line 9:
1. Make sure you have a Bugzilla account. You can create a new account [https://bugzilla.mozilla.org/createaccount.cgi here].<br />
1. Make sure you have a Bugzilla account. You can create a new account [https://bugzilla.mozilla.org/createaccount.cgi here].<br />
2. Create a [https://bugzilla.mozilla.org/enter_bug.cgi new bug] on bugzilla.mozilla.org <br />
2. Create a [https://bugzilla.mozilla.org/enter_bug.cgi new bug] on bugzilla.mozilla.org <br />
3. Select the affected product <br />
3. Select the affected product: <br />
[[File:Productchoice.png|400px|frameless|none]]<br />
[[File:Productchoice.png|400px|frameless|none]]<br />
4. Select the affected component (best guess is OK - we will re-assign as need be)<br />
4. Select the affected component (best guess is OK - we will re-assign as need be):<br />
[[File:Componentchoice.png|400px|frameless|none]]<br />
[[File:Componentchoice.png|400px|frameless|none]]<br />
5. Add a bug summary <br />
5. Add a bug summary <br />
Line 19: Line 19:
* point out vulnerable code (use [https://dxr.mozilla.org/mozilla-central/source/ DXR] or [http://searchfox.org/ searchfox] to link to code directly)  
* point out vulnerable code (use [https://dxr.mozilla.org/mozilla-central/source/ DXR] or [http://searchfox.org/ searchfox] to link to code directly)  
* attach debug output or output from a tool demonstrating the issue. <br />
* attach debug output or output from a tool demonstrating the issue. <br />
8. '''IMPORTANT: mark the bug as a "security" bug to keep it confidential'''<br />
8. '''IMPORTANT: mark the bug as a "security" bug to keep it confidential''':<br />
[[File:Securitybug.png|800px|frameless|none]]<br />
[[File:Securitybug.png|800px|frameless|none]]<br />
9. Double check your entry then Submit the bug. <br />
9. Double check your entry then Submit the bug. <br />
canmove, Confirmed users
1,220

edits