Closed Bug 555018 (CVE-2011-2996) Opened 14 years ago Closed 14 years ago

initialize nsChildView plugin ports

Categories

(Core :: Widget: Cocoa, defect)

All
macOS
defect
Not set
normal

Tracking

()

RESOLVED FIXED
mozilla2.0
Tracking Status
status2.0 --- unaffected
blocking1.9.2 --- .23+
status1.9.2 --- .23-fixed
status1.9.1 --- wanted

People

(Reporter: jaas, Assigned: jaas)

References

Details

(Keywords: crash, Whiteboard: [sg:moderate])

Attachments

(2 files)

Attached patch fix v1.0Splinter Review
We should initialize nsChildView plugin ports.
Attachment #434946 - Flags: review?(roc)
Blocks: 527280
pushed to mozilla-central

http://hg.mozilla.org/mozilla-central/rev/5e9d5bbf7596
Status: NEW → RESOLVED
Closed: 14 years ago
Resolution: --- → FIXED
This is a safe patch, we should take it on 1.9.2.
Attachment #434946 - Attachment is obsolete: true
Attachment #434953 - Flags: approval1.9.2.3?
Attachment #434946 - Attachment is obsolete: false
Attachment #434953 - Flags: approval1.9.2.4? → approval1.9.2.8?
Comment on attachment 434953 [details] [diff] [review]
fix v1.0 for 1.9.2

Is this still wanted on the 3.6 branch, or should we just forget about it?
Attachment #434953 - Flags: approval1.9.2.9? → approval1.9.2.18?
What's the benefit of taking this change?
If we don't initialize that structure it can contain pointers to random memory. It's a stability issue, and might also have security implications.
Comment on attachment 434953 [details] [diff] [review]
fix v1.0 for 1.9.2

Approved for 1.9.2.18, a=dveditz for release-drivers
Attachment #434953 - Flags: approval1.9.2.18? → approval1.9.2.18+
Group: core-security
Whiteboard: [sg:critical?]
Comment on attachment 434953 [details] [diff] [review]
fix v1.0 for 1.9.2

doesn't apply on 1.9.2 because there's a context diff around the union nsPluginPort line. Not sure if it's still safe to remove that or if there were other changes to the file that would require a different patch. fwiw the trunk still seems to have that line in it.
Attachment #434953 - Flags: approval1.9.2.18+ → approval1.9.2.18-
blocking1.9.2: --- → needed
Target Milestone: --- → mozilla2.0
blocking1.9.2: needed → .21+
Whiteboard: [sg:critical?] → [sg:moderate]
Alias: CVE-2011-2996
Group: core-security
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Creator:
Created:
Updated:
Size: