Closed Bug 1256491 Opened 9 years ago Closed 9 years ago

hunspell: heap-buffer-overflow read in [@SuggestMgr::leftcommonsubstring]

Categories

(Core :: Spelling checker, defect)

defect
Not set
normal

Tracking

()

RESOLVED FIXED
mozilla49
Tracking Status
firefox48 --- fixed

People

(Reporter: tsmith, Unassigned)

References

Details

(Keywords: crash, csectype-bounds, sec-moderate)

Attachments

(1 file)

Attached file call_stack.txt
Found in hunspell revision ded5b4c62c37084d216154e02e4d5e6efbd3ccfa To reproduce: create a test.txt file containing "abandonned abandoned" run ./src/tools/example tests/alias3.aff tests/base_utf.dic test.txt
Group: core-security → dom-core-security
Does the crash happen also in browser?
I think this is caused by Tyson using base_utf.dic. "abandonned" doesn't crash my Firefox.
this now passes in github hunspell master
Depends on: 1257902
Should be fixed on trunk by bug 1257902.
Status: NEW → RESOLVED
Closed: 9 years ago
Resolution: --- → FIXED
Target Milestone: --- → mozilla49
Group: dom-core-security → core-security-release
bug 1257902 was fixed in Firefox 47, not 48 or 49. :-)
Group: core-security-release
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: