Closed Bug 876243 Opened 11 years ago Closed 6 years ago

crash in memcpy | js_NewStringCopyN with Avast WebRep 8.0.1483 and below

Categories

(Core :: JavaScript Engine, defect)

21 Branch
x86
Windows 7
defect
Not set
critical

Tracking

()

RESOLVED WONTFIX
Tracking Status
firefox21 --- affected
firefox22 --- affected
firefox23 --- affected
firefox24 --- affected

People

(Reporter: scoobidiver, Unassigned)

Details

(Keywords: crash)

Crash Data

It's #66 browser crasher in 21.0, #103 in 22.0b2, #93 in 23.0a2, and #149 in 24.0a1.

It's correlated to an old version of Avast WebRep extension:
  memcpy | js_NewStringCopyN<int>(JSContext*, wchar_t const*, unsigned int)|EXCEPTION_ACCESS_VIOLATION_READ (103 crashes)
     72% (74/103) vs.   5% (3782/69132) wrc@avast.com
          4% (4/103) vs.   1% (474/69132) 7.0.1474
          1% (1/103) vs.   0% (56/69132) 8.0.1482
         67% (69/103) vs.   2% (1334/69132) 8.0.1483
          0% (0/103) vs.   2% (1327/69132) 8.0.1489

Signature 	memcpy | js_NewStringCopyN<int>(JSContext*, wchar_t const*, unsigned int) More Reports Search
UUID	c036d7a1-9600-4165-a7d6-e4d182130526
Date Processed	2013-05-26 10:30:43
Uptime	54
Last Crash	4.9 weeks before submission
Install Age	11.6 hours since version was first installed.
Install Time	2013-05-25 22:52:53
Product	Firefox
Version	24.0a1
Build ID	20130525031005
Release Channel	nightly
OS	Windows NT
OS Version	6.2.9200
Build Architecture	x86
Build Architecture Info	GenuineIntel family 6 model 37 stepping 5
Crash Reason	EXCEPTION_ACCESS_VIOLATION_READ
Crash Address	0x18f6c524
App Notes 	
AdapterVendorID: 0x8086, AdapterDeviceID: 0x0046, AdapterSubsysID: 04871025, AdapterDriverVersion: 8.15.10.2858
D2D? D2D+ DWrite? DWrite+ D3D10 Layers? D3D10 Layers+ 
Processor Notes 	sp-processor02_phx1_mozilla_com_32086:2012
EMCheckCompatibility	True
Adapter Vendor ID	0x8086
Adapter Device ID	0x0046
Total Virtual Memory	4294836224
Available Virtual Memory	3765321728
System Memory Use Percentage	27
Available Page File	10432421888
Available Physical Memory	4448813056

Frame 	Module 	Signature 	Source
0 	msvcr100.dll 	memcpy 	f:\dd\vctools\crt_bld\SELF_X86\crt\src\INTEL\memcpy.asm:185
1 	mozjs.dll 	js_NewStringCopyN<1> 	js/src/jsstr.cpp:3620
2 	mozjs.dll 	js::ScriptSource::substring 	js/src/jsscript.cpp:1258
3 	mozjs.dll 	JSScript::sourceData 	js/src/jsscript.cpp:1180
4 	mozjs.dll 	js::FunctionToString 	js/src/jsfun.cpp:633
5 	mozjs.dll 	fun_toStringHelper 	js/src/jsfun.cpp:764
6 	mozjs.dll 	fun_toString 	js/src/jsfun.cpp:782
...

More reports at:
https://crash-stats.mozilla.com/report/list?signature=memcpy+|+js_NewStringCopyN%3Cint%3E%28JSContext*%2C+wchar_t+const*%2C+unsigned+int%29
Assignee: general → nobody
Crash Signature: [@ memcpy | js_NewStringCopyN<int>(JSContext*, wchar_t const*, unsigned int)] [@ memcpy | js_NewStringCopyN(JSContext*, wchar_t const*, unsigned int) ] → [@ memcpy | js_NewStringCopyN<int>(JSContext*, wchar_t const*, unsigned int)] [@ memcpy | js_NewStringCopyN(JSContext*, wchar_t const*, unsigned int) ] [@ memcpy | js_NewStringCopyN<T>] [@ memcpy | js_NewStringCopyN ]
Closing because no crash reported since 12 weeks.
Status: NEW → RESOLVED
Closed: 6 years ago
Resolution: --- → WONTFIX
You need to log in before you can comment on or make changes to this bug.