ABORT: file gecko/ipc/chromium/src/base/pickle.cc, line 198 (Pickle::ReadSize)

NEW
Unassigned

Status

()

--
critical
7 years ago
3 years ago

People

(Reporter: posidron, Unassigned)

Tracking

(Blocks: 1 bug, {crash})

Trunk
ARM
Gonk (Firefox OS)
crash
Points:
---
Dependency tree / graph

Firefox Tracking Flags

(blocking-basecamp:-)

Details

(crash signature)

Attachments

(1 attachment)

(Reporter)

Description

7 years ago
Created attachment 648776 [details]
callstack

In this scenario the Write|Datatype|() functions of Pickle were hooked to use abnormal values.

This abort happened during the launch of Firefox.

Let me know if you need further information.
blocking-basecamp: --- → ?
Whiteboard: [blocked-on-input Chris Jones]
This is a way for buggy/malicious content processes to DoS the phone.  It's one of very many.

Definitely a polish issue, but not a blocker.
blocking-basecamp: ? → -
Whiteboard: [blocked-on-input Chris Jones]

Updated

6 years ago
Crash Signature: [@ mozalloc_abort(char const* const) | NS_DebugBreak | mozilla::Logger::~Logger()]

Updated

6 years ago
Summary: ABORT: file gecko/ipc/chromium/src/base/pickle.cc, line 198 → ABORT: file gecko/ipc/chromium/src/base/pickle.cc, line 198 (Pickle::ReadSize)

Comment 2

5 years ago
Is there a test case for this?
Duplicate of this bug: 807264
Duplicate of this bug: 807262
Duplicate of this bug: 782945

Updated

3 years ago
Crash Signature: [@ mozalloc_abort(char const* const) | NS_DebugBreak | mozilla::Logger::~Logger()] → [@ mozalloc_abort(char const* const) | NS_DebugBreak | mozilla::Logger::~Logger()] [@ mozalloc_abort | NS_DebugBreak | mozilla::Logger::~Logger]
You need to log in before you can comment on or make changes to this bug.