Closed
Bug 443424
Opened 18 years ago
Closed 8 years ago
Incorrect Message for security error
Categories
(Core :: XPConnect, defect)
Tracking
()
RESOLVED
INACTIVE
People
(Reporter: johnjbarton, Unassigned)
References
(Blocks 1 open bug)
Details
(Keywords: sec-other, Whiteboard: [sg:nse] testcase from security bug 344751)
The error message that results when the test case for this bug is run is
incorrect in two ways.
1) The file name and line number are
wrong:[fileName]=XPCSafeJSObjectWrapper.cpp;
[lineNo]=445;
2) The error level is marked as "info" rather than "error"
Test case:
https://bugzilla.mozilla.org/attachment.cgi?id=307990
Comment 1•18 years ago
|
||
How is this different from bug 442489? Why is this bug report security-sensitive?
| Reporter | ||
Comment 2•18 years ago
|
||
(In reply to comment #1)
> How is this different from bug 442489?
I don't see any reason to thing that this bug overlaps 442489. This error message looks completely different and arises from a completely different circumstance. Of course it may have the same cause, which would mean one fix gets two bugs.
> Why is this bug report
> security-sensitive?
>
The example is an exploit.
Comment 3•18 years ago
|
||
(In reply to comment #0)
> 1) The file name and line number are
> wrong:[fileName]=XPCSafeJSObjectWrapper.cpp;
> [lineNo]=445;
See bug 246699 comment 51.
Component: Security → XPConnect
Product: Firefox → Core
QA Contact: firefox → xpconnect
| Reporter | ||
Comment 4•18 years ago
|
||
The content of the error message contains the correct file name, so at the point that the error is generated the correct filename is available. It should not be difficult to get the line number from the call stack.
Updated•18 years ago
|
Whiteboard: [sg:nse] testcase from security bug 344751
Comment 5•17 years ago
|
||
Unhiding this bug. Doing so does not unhide the referenced attachment and nothing about the error message itself is security sensitive.
Group: core-security
Comment 6•8 years ago
|
||
Per policy at https://wiki.mozilla.org/Bug_Triage/Projects/Bug_Handling/Bug_Husbandry#Inactive_Bugs. If this bug is not an enhancement request or a bug not present in a supported release of Firefox, then it may be reopened.
Status: NEW → RESOLVED
Closed: 8 years ago
Resolution: --- → INACTIVE
You need to log in
before you can comment on or make changes to this bug.
Description
•