Closed Bug 740707 Opened 14 years ago Closed 14 years ago

cross_fuzz crash in mozilla::dom::Navigator::GetMozBattery

Categories

(Core :: DOM: Core & HTML, defect)

defect
Not set
critical

Tracking

()

RESOLVED FIXED
mozilla14
Tracking Status
firefox11 --- wontfix
firefox12 --- wontfix
firefox13 --- wontfix
firefox14 --- verified
firefox-esr10 --- wontfix

People

(Reporter: cpeterson, Assigned: mounir)

References

()

Details

(Keywords: crash, csectype-dos, reproducible)

Crash Data

Attachments

(1 file)

Keywords: reproducible
Component: XPConnect → DOM: Core & HTML
QA Contact: xpconnect → general
I can't reproduce that on my Linux laptop. Is that Mac only?
I only have Mac test machines. I reproduced it on Mac OS X 10.6 and 10.7.
Attached patch PatchSplinter Review
Stupid mistake... sorry about that :(
Assignee: nobody → mounir
Status: NEW → ASSIGNED
Attachment #611104 - Flags: review?(justin.lebar+bug)
OS: Mac OS X → All
Attachment #611104 - Flags: review?(justin.lebar+bug) → review+
Attachment #611104 - Flags: checkin+
Crash Signature: [@ mozilla::dom::Navigator::GetMozBattery] → [@ mozilla::dom::Navigator::GetMozBattery ]
Status: ASSIGNED → RESOLVED
Closed: 14 years ago
Resolution: --- → FIXED
Target Milestone: --- → mozilla14
I wonder why my fuzzer missed this bug. Is there a reduced testcase?
I haven't done one but maybe we can ask QA to do one?
seems ff 13.0.2 is affected, please see Bug 767947
This has been fixed in Firefox 14, see the target milestone.
yes i saw, but why not in 13.x ?
We could indeed have pushed that to Firefox 13 but it's now too late.
Keywords: csec-dos
(In reply to David Maciejak from comment #10) > yes i saw, but why not in 13.x ? This is not an exploitable crash and is not a major stability problem since it's a new, little-used feature. There is no practical user benefit to the disruption of an out-of-cycle release.
Verified on Ubuntu 12.04, Mac OS X 10.6 and Mac OS X 10.7 that Firefox 14 beta 10 does not crash when using the STR from the Description. Mozilla/5.0 (X11; Linux i686; rv:14.0) Gecko/20100101 Firefox/14.0 Mozilla/5.0 (Macintosh; Intel Mac OS X 10.6; rv:14.0) Gecko/20100101 Firefox/14.0 Mozilla/5.0 (Macintosh; Intel Mac OS X 10.7; rv:14.0) Gecko/20100101 Firefox/14.0 Also, checked in Socorro and there are no crashes on Firefox 14.
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: