Closed Bug 1413033 Opened 8 years ago Closed 7 years ago

Crash in js::ZoneGroup::enter called from AutoJSAPI::InitInternal()

Categories

(Core :: JavaScript Engine, defect, P2)

Unspecified
Windows 10
defect

Tracking

()

RESOLVED FIXED
mozilla61
Tracking Status
firefox-esr52 --- unaffected
firefox-esr60 --- wontfix
firefox56 --- wontfix
firefox57 --- wontfix
firefox58 --- wontfix
firefox59 --- wontfix
firefox60 --- wontfix
firefox61 --- fixed

People

(Reporter: jesup, Assigned: jandem)

References

Details

(5 keywords, Whiteboard: [adv-main61+][post-critsmash-triage])

Crash Data

+++ This bug was initially created as a clone of Bug #1394223 +++ A second bug with this signature, called from dom::AutoJSAPI::InitInternal() via emplace() Crashes are a mix of wildptrs and UAFs, and include EXEC crashes on wildptr's -> sec-critical
Group: core-security → javascript-core-security
Too late for 56, may be too late for 57 as we are heading into the RC build on Monday.
P1 is probably not right for a low volume crash; clearing for re-triage.
Priority: P1 → --
Kannan?
Flags: needinfo?(kvijayan)
Priority: -- → P2
Assignee: nobody → kvijayan
Kannan, any updates on this bug? The needinfo has been pending for quite some time.
This bug has been left without any proper developer attention for almost half a year. Steven, can you help assign this to someone with more bandwidth to fix it?
Flags: needinfo?(sdetar)
Bug 1449135 removed ZoneGroup::enter so this signature is gone.
Assignee: kvijayan → jdemooij
Status: NEW → RESOLVED
Closed: 7 years ago
Flags: needinfo?(sdetar)
Flags: needinfo?(nihsanullah)
Flags: needinfo?(kvijayan)
Resolution: --- → FIXED
Target Milestone: --- → mozilla61
Group: javascript-core-security → core-security-release
Whiteboard: [adv-main61+]
Flags: qe-verify-
Whiteboard: [adv-main61+] → [adv-main61+][post-critsmash-triage]
Group: core-security-release
You need to log in before you can comment on or make changes to this bug.