Use after Free outside sandbox
Categories
(Core :: Printing: Setup, task)
Tracking
()
People
(Reporter: hiimbogdan, Unassigned, NeedInfo)
Details
(Keywords: reporter-external, Whiteboard: [reporter-external] [client-bounty-form] [verif?])
Attachments
(1 file)
|
274 bytes,
text/html
|
Details |
UaF outside the sandbox (Print in onunload)
Steps to reproduce the problem:
- Open poc.html in firefox
Firefox version: 75.0
OS: Windows 10 build 1909 (64 bit)
Comment 1•6 years ago
|
||
I can't reproduce a crash, never mind a uaf, on either Windows or Mac. Can you provide more details? Does it depend on actually printing (perhaps with a specific printer / driver), or canceling the dialog, or something else? And can you reproduce on nightly? Do you have any submitted crashreports from these crashes that you can link to?
I'd also note that the navigation seems to not complete for me until after I dismiss/accept the print dialog. Do you see the same thing or no?
Comment 2•6 years ago
|
||
I tried reproducing this on Linux with ASan, no luck. An ASan trace would be nice to have, if there is a use-after-free.
Comment 3•6 years ago
|
||
Or even if you don't have an ASAN build, a regular crash link from about:crashes would help with some clues.
Comment 4•6 years ago
|
||
Don't know where to go from here without more info.
Comment 5•5 years ago
|
||
Marking bounty-, if the reporter re-appears we can re-evaluate.
Updated•2 years ago
|
Updated•1 year ago
|
Description
•