WebAudio heap-buffer-overflow crash [@speex_resampler_process_float]

RESOLVED FIXED in Firefox 24

Status

()

defect
--
critical
RESOLVED FIXED
6 years ago
5 years ago

People

(Reporter: posidron, Assigned: Ehsan)

Tracking

(Blocks 1 bug, 4 keywords)

Trunk
mozilla24
x86_64
macOS
Points:
---
Dependency tree / graph

Firefox Tracking Flags

(firefox21 unaffected, firefox22 disabled, firefox23- disabled, firefox24+ fixed, firefox-esr17 unaffected, b2g18 unaffected)

Details

(Whiteboard: [adv-main24-])

Attachments

(3 attachments, 1 obsolete attachment)

Posted file testcase
Tested with m-i changeset: 132700:cf2106c1f0c7 and the patches in bug 874915 and bug 874869.

NOTE: with those patches applied bug 874934 is no longer reproducible.
Posted file callstack
:ehsan, I will most likely reduce the testcase later or tomorrow, I just wanted to file this bug as early as possible.
Hey Ehsan, we're going to be triaging the latest critical webaudio bugs in about 2 hours. Do you want to beat us to it or just wait for us to assign them to you? (Sorry man)

Also this is nightly only right?
Flags: needinfo?(ehsan)
Blocks: 875414
Posted patch Patch (v1) (obsolete) — Splinter Review
Assignee: nobody → ehsan
Status: NEW → ASSIGNED
Attachment #753427 - Flags: review?(roc)
Flags: needinfo?(ehsan)
Duplicate of this bug: 875152
(In reply to David Bolter [:davidb] from comment #3)
> Hey Ehsan, we're going to be triaging the latest critical webaudio bugs in
> about 2 hours. Do you want to beat us to it or just wait for us to assign
> them to you? (Sorry man)

See comment 4.  ;-)

> Also this is nightly only right?

Web Audio is only enabled by default on Nightly and Aurora.  This is Nightly, Aurora and it will also affect Beta users who have the media.webaudio.enabled pref enabled.
Triaging with Ehsan. Note he just told me we'll likely disable for 23 so we may want to update those flags but let's air on the side of caution until that happens.
Attachment #753497 - Flags: review?(roc)
Attachment #753427 - Attachment is obsolete: true
Attachment #753427 - Flags: review?(roc)
indeed - tracking whether we disable or not, so it stays on the radar
https://hg.mozilla.org/mozilla-central/rev/454f2e5ff75f
Status: ASSIGNED → RESOLVED
Closed: 6 years ago
Resolution: --- → FIXED
Target Milestone: --- → mozilla24
Blocks: 875617
Mass moving Web Audio bugs to the Web Audio component.  Filter on duckityduck.
Component: Video/Audio → Web Audio
No longer tracking for FF23
Whiteboard: [adv-main24-]
Group: core-security
You need to log in before you can comment on or make changes to this bug.