Closed
Bug 505738
Opened 15 years ago
Closed 13 years ago
nsScriptableRegion::GetRects doesn't handle failure from JS_NewArrayObject [@ JS_DefineElement - nsScriptableRegion::GetRects]
Categories
(Core :: Graphics, defect)
Core
Graphics
Tracking
()
RESOLVED
FIXED
mozilla11
People
(Reporter: timeless, Assigned: timeless)
References
(Blocks 1 open bug, )
Details
(Keywords: coverity, crash)
Crash Data
Attachments
(1 file, 1 obsolete file)
647 bytes,
patch
|
gal
:
review+
|
Details | Diff | Splinter Review |
188 JSObject *destArray = JS_NewArrayObject(cx, mRectSet->mNumRects*4, NULL);
JS_NewArrayObject will return null on oom
and you'll crash here:
196 JS_DefineElement(cx, destArray, n, INT_TO_JSVAL(rect.x), NULL, NULL, JSPROP_ENUMERATE);
Attachment #390177 -
Flags: review?(vladimir) → review?(jmuizelaar)
Attachment #390177 -
Attachment is obsolete: true
Attachment #391615 -
Flags: review?(jmuizelaar)
Attachment #390177 -
Flags: review?(jmuizelaar)
Comment 3•15 years ago
|
||
Comment on attachment 391615 [details] [diff] [review]
updated reviewer
I'm not a good reviewer for this.
Attachment #391615 -
Flags: review?(jmuizelaar)
Updated•13 years ago
|
Crash Signature: [@ JS_DefineElement - nsScriptableRegion::GetRects]
Updated•13 years ago
|
Attachment #391615 -
Flags: review?(gal)
Updated•13 years ago
|
Attachment #391615 -
Flags: review?(gal) → review+
Comment 4•13 years ago
|
||
Status: ASSIGNED → RESOLVED
Closed: 13 years ago
Resolution: --- → FIXED
Target Milestone: --- → mozilla11
Updated•6 years ago
|
Blocks: coverity-analysis
You need to log in
before you can comment on or make changes to this bug.
Description
•