Closed Bug 1551452 Opened 5 years ago Closed 5 years ago

The Firefox Tab will crash when revoking Temporary Permissions for screen sharing

Categories

(Core :: WebRTC, defect, P2)

Desktop
All
defect

Tracking

()

RESOLVED DUPLICATE of bug 1550955
Tracking Status
firefox66 --- unaffected
firefox67 --- unaffected
firefox67.0.1 --- unaffected
firefox68 --- fixed

People

(Reporter: rdoghi, Assigned: dminor)

Details

(Keywords: csectype-uaf, regression, sec-moderate)

Attachments

(1 file)

[Affected versions]:
Nightly 68.0a1

[Affected platforms]:
Platforms: ALL

Steps :

  1. Launch the Firefox browser and reach https://mozilla.github.io/webrtc-landing/gum_test.html
  2. Click the Window Button and Allow screen Sharing of a Screen.
  3. Click the Site Information Panel and Revoke the Temporary Allowed Permissions.

Expected Results :
The Page should stop sharing the screen, And the Success text should be displayed.

Actual Results :
The Firefox Tab crashes with the "Gah your tab just crashed" text.

I tried to do a mozregression but it seems theres not enough data for a more accurate find.
Last GOOD: https://hg.mozilla.org/mozilla-central/pushloghtml?fromchange=579cc975268f03bcc335f099a25215b87836a4ef&tochange=414f37afbe07fd8e5164daf8fa50b38cb64c83ec
First BAD: https://hg.mozilla.org/mozilla-central/pushloghtml?fromchange=04bd7929b499d25fc538e516fc3de1aa6e9d79dc&tochange=414f37afbe07fd8e5164daf8fa50b38cb64c83ec

Attached video 2019-05-14_11h42_05.mp4
Assignee: nobody → dminor
Priority: -- → P2

This reproduces easily on a Linux system. The crash is caused by a use after free.

Group: core-security
Keywords: csectype-uaf

It appears that this crash is only reachable from chrome and not from content, so perhaps it doesn't need to be a sec bug after all.

It should probably still be a sec bug even though it is from chrome, but I think it can be sec-moderate.

Keywords: sec-moderate

Bug 1550955 is another crash involving stopping sharing. I don't know if it is the same issue or not.

Group: core-security → media-core-security
See Also: → 1550955

Looks like the same issue to me. Thanks for pointing that out!

Status: NEW → RESOLVED
Closed: 5 years ago
Resolution: --- → DUPLICATE
See Also: 1550955
Group: media-core-security
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: