(FTPDirListConv) Assertion failure: CheckCapacity(aLength) (String is too large.), at xpcom/string/nsTSubstring.h:876
Categories
(Core Graveyard :: Networking: FTP, defect, P2)
Tracking
(firefox-esr52 wontfix, firefox-esr60 wontfix, firefox61 wontfix, firefox62 wontfix, firefox63 wontfix, firefox67 wontfix, firefox68 wontfix, firefox69 fixed)
People
(Reporter: u473386, Assigned: michal)
References
Details
(Keywords: sec-other, Whiteboard: [necko-triaged][adv-main63-][post-critsmash-triage][adv-main69-])
Attachments
(4 files, 1 obsolete file)
Updated•7 years ago
|
Comment 2•7 years ago
|
||
Updated•7 years ago
|
Updated•7 years ago
|
Comment 3•7 years ago
|
||
Comment 5•7 years ago
|
||
Comment 7•7 years ago
|
||
Comment 8•7 years ago
|
||
Updated•7 years ago
|
Updated•7 years ago
|
Comment 10•7 years ago
|
||
Comment 11•7 years ago
|
||
Comment 12•7 years ago
|
||
Comment 13•7 years ago
|
||
Comment 14•7 years ago
|
||
Comment 15•7 years ago
|
||
Comment 16•7 years ago
|
||
Updated•7 years ago
|
| Reporter | ||
Comment 18•7 years ago
|
||
| Reporter | ||
Comment 19•7 years ago
|
||
| Reporter | ||
Comment 20•7 years ago
|
||
Comment 21•7 years ago
|
||
Comment 23•7 years ago
|
||
Comment 25•7 years ago
|
||
| Reporter | ||
Comment 26•7 years ago
|
||
Comment 27•7 years ago
|
||
Updated•7 years ago
|
Comment 28•7 years ago
|
||
Updated•7 years ago
|
| Reporter | ||
Comment 29•7 years ago
|
||
Comment 30•7 years ago
|
||
Comment 31•7 years ago
|
||
Comment 32•7 years ago
|
||
| Reporter | ||
Comment 33•7 years ago
|
||
Comment 34•7 years ago
|
||
Updated•7 years ago
|
Comment 35•7 years ago
|
||
| Reporter | ||
Comment 36•7 years ago
|
||
Comment 37•6 years ago
|
||
Comment 38•6 years ago
|
||
This needs to be fixed because it is blocking any kind of additional fuzz testing on the FTP code (which we consider important to perform as this code is really old and not well-tested).
Comment 39•6 years ago
|
||
(In reply to Christian Holler (:decoder) from comment #38)
This needs to be fixed because it is blocking any kind of additional fuzz testing on the FTP code (which we consider important to perform as this code is really old and not well-tested).
Move this to P2 for now.
I'll also bring this to our round table of necko meeting.
| Assignee | ||
Comment 41•6 years ago
|
||
The parsing code uses filename without checking its presence. This patch ensures that the filename contains at least one non white space character.
Comment 42•6 years ago
|
||
https://hg.mozilla.org/integration/autoland/rev/7e57bb8c2fdc1d1764f945fcc242993ad279fe04
https://hg.mozilla.org/mozilla-central/rev/7e57bb8c2fdc
Comment 43•6 years ago
|
||
Has the security diagnosis from comment 15/16 changed or is this still a wontfix for uplifts?
| Assignee | ||
Comment 44•6 years ago
|
||
I think the severity hasn't changed. result.fe_fnlen will always be slightly less than UINT32_MAX and assertion in
nsTSubstring::nsTSubstring is a release assertion, so it should always assert and we won't access memory out of the buffer.
Updated•6 years ago
|
Updated•6 years ago
|
Updated•6 years ago
|
Updated•6 years ago
|
Updated•5 years ago
|
Updated•1 year ago
|
Description
•