Security/Fileabug

From MozillaWiki
Jump to navigation Jump to search

Filing A Security Bug

Mozilla relies on the security community to help secure our products and websites by reporting security issues. This page provides information on how to use Bugzilla to submit a security issue.

Steps to file a bug

  1. Make sure you have a Bugzilla account. You can create a new account here.
  2. Create a new bug on bugzilla.mozilla.org
  3. Select the affected product
  4. Select the affected component (best guess is OK - we will re-assign as need be)
  5. Add a bug summary
  6. Add a bug description
  7. Add as much information as possible: a "proof of concept" testcase, point out vulnerable code, attach debug output or output from a tool demonstrating the issue.
  8. IMPORTANT: mark the bug as a "security" bug to keep it confidential