Closed Bug 443424 Opened 18 years ago Closed 8 years ago

Incorrect Message for security error

Categories

(Core :: XPConnect, defect)

x86
Windows XP
defect
Not set
normal

Tracking

()

RESOLVED INACTIVE

People

(Reporter: johnjbarton, Unassigned)

References

(Blocks 1 open bug)

Details

(Keywords: sec-other, Whiteboard: [sg:nse] testcase from security bug 344751)

The error message that results when the test case for this bug is run is incorrect in two ways. 1) The file name and line number are wrong:[fileName]=XPCSafeJSObjectWrapper.cpp; [lineNo]=445; 2) The error level is marked as "info" rather than "error" Test case: https://bugzilla.mozilla.org/attachment.cgi?id=307990
How is this different from bug 442489? Why is this bug report security-sensitive?
(In reply to comment #1) > How is this different from bug 442489? I don't see any reason to thing that this bug overlaps 442489. This error message looks completely different and arises from a completely different circumstance. Of course it may have the same cause, which would mean one fix gets two bugs. > Why is this bug report > security-sensitive? > The example is an exploit.
(In reply to comment #0) > 1) The file name and line number are > wrong:[fileName]=XPCSafeJSObjectWrapper.cpp; > [lineNo]=445; See bug 246699 comment 51.
Component: Security → XPConnect
Product: Firefox → Core
QA Contact: firefox → xpconnect
The content of the error message contains the correct file name, so at the point that the error is generated the correct filename is available. It should not be difficult to get the line number from the call stack.
Whiteboard: [sg:nse] testcase from security bug 344751
Unhiding this bug. Doing so does not unhide the referenced attachment and nothing about the error message itself is security sensitive.
Group: core-security
Per policy at https://wiki.mozilla.org/Bug_Triage/Projects/Bug_Handling/Bug_Husbandry#Inactive_Bugs. If this bug is not an enhancement request or a bug not present in a supported release of Firefox, then it may be reopened.
Status: NEW → RESOLVED
Closed: 8 years ago
Resolution: --- → INACTIVE
You need to log in before you can comment on or make changes to this bug.