The Firefox Tab will crash when revoking Temporary Permissions for screen sharing
Categories
(Core :: WebRTC, defect, P2)
Tracking
()
Tracking | Status | |
---|---|---|
firefox66 | --- | unaffected |
firefox67 | --- | unaffected |
firefox67.0.1 | --- | unaffected |
firefox68 | --- | fixed |
People
(Reporter: rdoghi, Assigned: dminor)
Details
(Keywords: csectype-uaf, regression, sec-moderate)
Attachments
(1 file)
901.51 KB,
video/mp4
|
Details |
[Affected versions]:
Nightly 68.0a1
[Affected platforms]:
Platforms: ALL
Steps :
- Launch the Firefox browser and reach https://mozilla.github.io/webrtc-landing/gum_test.html
- Click the Window Button and Allow screen Sharing of a Screen.
- Click the Site Information Panel and Revoke the Temporary Allowed Permissions.
Expected Results :
The Page should stop sharing the screen, And the Success text should be displayed.
Actual Results :
The Firefox Tab crashes with the "Gah your tab just crashed" text.
I tried to do a mozregression but it seems theres not enough data for a more accurate find.
Last GOOD: https://hg.mozilla.org/mozilla-central/pushloghtml?fromchange=579cc975268f03bcc335f099a25215b87836a4ef&tochange=414f37afbe07fd8e5164daf8fa50b38cb64c83ec
First BAD: https://hg.mozilla.org/mozilla-central/pushloghtml?fromchange=04bd7929b499d25fc538e516fc3de1aa6e9d79dc&tochange=414f37afbe07fd8e5164daf8fa50b38cb64c83ec
Reporter | ||
Updated•5 years ago
|
Reporter | ||
Comment 1•5 years ago
|
||
Assignee | ||
Updated•5 years ago
|
Assignee | ||
Comment 2•5 years ago
|
||
This reproduces easily on a Linux system. The crash is caused by a use after free.
Assignee | ||
Comment 3•5 years ago
|
||
It appears that this crash is only reachable from chrome and not from content, so perhaps it doesn't need to be a sec bug after all.
Comment 4•5 years ago
|
||
It should probably still be a sec bug even though it is from chrome, but I think it can be sec-moderate.
Updated•5 years ago
|
Comment 5•5 years ago
|
||
Bug 1550955 is another crash involving stopping sharing. I don't know if it is the same issue or not.
Assignee | ||
Comment 6•5 years ago
|
||
Looks like the same issue to me. Thanks for pointing that out!
Updated•5 years ago
|
Updated•1 year ago
|
Description
•