Closed Bug 780219 Opened 12 years ago Closed 5 years ago

ABORT: file gecko/ipc/chromium/src/base/pickle.cc, line 198 (Pickle::ReadSize)

Categories

(Core :: IPC, defect)

ARM
Gonk (Firefox OS)
defect
Not set
critical

Tracking

()

RESOLVED WORKSFORME
blocking-basecamp -

People

(Reporter: posidron, Unassigned)

References

(Blocks 1 open bug)

Details

(Keywords: crash)

Crash Data

Attachments

(1 file)

Attached file callstack
In this scenario the Write|Datatype|() functions of Pickle were hooked to use abnormal values.

This abort happened during the launch of Firefox.

Let me know if you need further information.
blocking-basecamp: --- → ?
Whiteboard: [blocked-on-input Chris Jones]
This is a way for buggy/malicious content processes to DoS the phone.  It's one of very many.

Definitely a polish issue, but not a blocker.
blocking-basecamp: ? → -
Whiteboard: [blocked-on-input Chris Jones]
Crash Signature: [@ mozalloc_abort(char const* const) | NS_DebugBreak | mozilla::Logger::~Logger()]
Summary: ABORT: file gecko/ipc/chromium/src/base/pickle.cc, line 198 → ABORT: file gecko/ipc/chromium/src/base/pickle.cc, line 198 (Pickle::ReadSize)
Is there a test case for this?
Crash Signature: [@ mozalloc_abort(char const* const) | NS_DebugBreak | mozilla::Logger::~Logger()] → [@ mozalloc_abort(char const* const) | NS_DebugBreak | mozilla::Logger::~Logger()] [@ mozalloc_abort | NS_DebugBreak | mozilla::Logger::~Logger]

Closing because no crashes reported for 12 weeks.

Status: NEW → RESOLVED
Closed: 5 years ago
Resolution: --- → WORKSFORME
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: