Closed Bug 327524 Opened 18 years ago Closed 18 years ago

Crash when using crypto.generateCRMFRequest(document.documentElement);

Categories

(Core :: Security: PSM, defect)

x86
Windows XP
defect
Not set
critical

Tracking

()

RESOLVED FIXED

People

(Reporter: martijn.martijn, Assigned: KaiE)

Details

(4 keywords, Whiteboard: [sg:dupe 330900])

Attachments

(1 file)

I'm filing this mainly as security sensitive, because I got the idea from bug 327126, but I guess it's probably not security sensitive.

See upcoming testcase, which crashes current trunk Mozilla build. 
It also crashes Mozilla1.7.12, so no (recent) regression.


Talkback ID: TB15160940G

0x00110111
js_GetSlotThreadSafe  [c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/js/src/jslock.c, line 592]
JS_GetPrivate  [c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/js/src/jsapi.c, line 2153]
nsScriptSecurityManager::GetFramePrincipal  [c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/caps/src/nsScriptSecurityManager.cpp, line 2019]
nsScriptSecurityManager::GetPrincipalAndFrame  [c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/caps/src/nsScriptSecurityManager.cpp, line 2050]
nsScriptSecurityManager::GetSubjectPrincipal  [c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/caps/src/nsScriptSecurityManager.cpp, line 2092]
nsScriptSecurityManager::doGetSubjectPrincipal  [c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/caps/src/nsScriptSecurityManager.cpp, line 1690]
nsScriptSecurityManager::SubjectPrincipalIsSystem  [c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/caps/src/nsScriptSecurityManager.cpp, line 1725]
nsContentUtils::IsCallerChrome  [c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/content/base/src/nsContentUtils.cpp, line 1016]
PresShell::HandleEventInternal  [c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/layout/base/nsPresShell.cpp, line 6051]
PresShell::HandleEvent  [c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/layout/base/nsPresShell.cpp, line 5858]
nsViewManager::HandleEvent  [c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/view/src/nsViewManager.cpp, line 1725]
nsViewManager::DispatchEvent  [c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/view/src/nsViewManager.cpp, line 1678]
HandleEvent  [c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/view/src/nsView.cpp, line 175]
nsWindow::DispatchEvent  [c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/widget/src/windows/nsWindow.cpp, line 1036]
nsWindow::DispatchFocus  [c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/widget/src/windows/nsWindow.cpp, line 6068]
nsWindow::ProcessMessage  [c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/widget/src/windows/nsWindow.cpp, line 4640]
nsWindow::WindowProc  [c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/widget/src/windows/nsWindow.cpp, line 1225]
USER32.dll + 0x27b17 (0x77d37b17)
USER32.dll + 0x2cdce (0x77d3cdce)
USER32.dll + 0x459d (0x77d1459d)
USER32.dll + 0x47b4 (0x77d147b4)
ntdll.dll + 0x2589f (0x77f6589f)
USER32.dll + 0x96ce (0x77d196ce)
PeekKeyAndIMEMessage  [c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/widget/src/windows/nsAppShell.cpp, line 91]
nsAppShell::Run  [c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/widget/src/windows/nsAppShell.cpp, line 128]
nsAppStartup::Run  [c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/toolkit/components/startup/src/nsAppStartup.cpp, line 162]
main  [c:/builds/tinderbox/Fx-Trunk/WINNT_5.2_Depend/mozilla/browser/app/nsBrowserApp.cpp, line 61]
kernel32.dll + 0x1eb69 (0x77e5eb69)
I get a similar stack, except in nsScriptSecurityManager::GetFramePrincipal calling JS_GetFrameFunctionObject.
Assignee: dveditz → kengert
Component: Security → Security: PSM
QA Contact: toolkit
Doesn't crash anymore in 2006-03-26 build, most likely fixed by bug 330900.
Status: NEW → RESOLVED
Closed: 18 years ago
Resolution: --- → FIXED
Whiteboard: [sg:dupe 330900]
Group: security
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: