Closed
Bug 1200345
Opened 9 years ago
Closed 9 years ago
JS::ubi::Node comments should mention security concerns
Categories
(Core :: JavaScript Engine, defect)
Core
JavaScript Engine
Tracking
()
RESOLVED
FIXED
mozilla43
Tracking | Status | |
---|---|---|
firefox43 | --- | fixed |
People
(Reporter: jimb, Assigned: jimb)
Details
Attachments
(1 file)
Since analyses on the ubi::Node graph are operating on data influenced by content, they must be robust when consuming graphs produced by hostile code. The comments in js/public/UbiNode.h should point this out.
Attachment #8654990 -
Flags: review?(nfitzgerald)
Updated•9 years ago
|
Assignee: nobody → jimb
Status: NEW → ASSIGNED
Comment 1•9 years ago
|
||
Comment on attachment 8654990 [details] [diff] [review] Add comment to js/public/UbiNode.h warning about operating on graphs constructed by hostile code. Review of attachment 8654990 [details] [diff] [review]: ----------------------------------------------------------------- Awesome, thanks!
Attachment #8654990 -
Flags: review?(nfitzgerald) → review+
Comment 2•9 years ago
|
||
+CC sfink, just FYI since you're the other person primarily looking at and reviewing ubi::Node stuff.
Comment 4•9 years ago
|
||
https://hg.mozilla.org/mozilla-central/rev/8985a835958c
Status: ASSIGNED → RESOLVED
Closed: 9 years ago
status-firefox43:
--- → fixed
Resolution: --- → FIXED
Target Milestone: --- → mozilla43
Comment 5•9 years ago
|
||
Thanks, I hadn't really thought about that angle. It's a good thing to keep in mind.
You need to log in
before you can comment on or make changes to this bug.
Description
•