The default bug view has changed. See this FAQ.

nsScriptableRegion::GetRects doesn't handle failure from JS_NewArrayObject [@ JS_DefineElement - nsScriptableRegion::GetRects]

RESOLVED FIXED in mozilla11

Status

()

Core
Graphics
--
critical
RESOLVED FIXED
8 years ago
5 years ago

People

(Reporter: timeless, Assigned: timeless)

Tracking

({coverity, crash})

Trunk
mozilla11
coverity, crash
Points:
---

Firefox Tracking Flags

(Not tracked)

Details

(crash signature, URL)

Attachments

(1 attachment, 1 obsolete attachment)

647 bytes, patch
gal
: review+
Details | Diff | Splinter Review
(Assignee)

Description

8 years ago
188   JSObject *destArray = JS_NewArrayObject(cx, mRectSet->mNumRects*4, NULL);
JS_NewArrayObject will return null on oom

and you'll crash here:
196     JS_DefineElement(cx, destArray, n, INT_TO_JSVAL(rect.x), NULL, NULL, JSPROP_ENUMERATE);
(Assignee)

Comment 1

8 years ago
Created attachment 390177 [details] [diff] [review]
patch
Assignee: nobody → timeless
Status: NEW → ASSIGNED
Attachment #390177 - Flags: review?(vladimir)
Attachment #390177 - Flags: review?(vladimir) → review?(jmuizelaar)
(Assignee)

Comment 2

8 years ago
Created attachment 391615 [details] [diff] [review]
updated reviewer
Attachment #390177 - Attachment is obsolete: true
Attachment #391615 - Flags: review?(jmuizelaar)
Attachment #390177 - Flags: review?(jmuizelaar)
Comment on attachment 391615 [details] [diff] [review]
updated reviewer

I'm not a good reviewer for this.
Attachment #391615 - Flags: review?(jmuizelaar)
Crash Signature: [@ JS_DefineElement - nsScriptableRegion::GetRects]

Updated

5 years ago
Attachment #391615 - Flags: review?(gal)

Updated

5 years ago
Attachment #391615 - Flags: review?(gal) → review+
https://hg.mozilla.org/mozilla-central/rev/78de2c2bdad5
Status: ASSIGNED → RESOLVED
Last Resolved: 5 years ago
Resolution: --- → FIXED
Target Milestone: --- → mozilla11
You need to log in before you can comment on or make changes to this bug.