crash in memcpy | js_NewStringCopyN with Avast WebRep 8.0.1483 and below

RESOLVED WONTFIX

Status

()

--
critical
RESOLVED WONTFIX
6 years ago
a month ago

People

(Reporter: scoobidiver, Unassigned)

Tracking

({crash})

21 Branch
x86
Windows 7
crash
Points:
---

Firefox Tracking Flags

(firefox21 affected, firefox22 affected, firefox23 affected, firefox24 affected)

Details

(crash signature)

(Reporter)

Description

6 years ago
It's #66 browser crasher in 21.0, #103 in 22.0b2, #93 in 23.0a2, and #149 in 24.0a1.

It's correlated to an old version of Avast WebRep extension:
  memcpy | js_NewStringCopyN<int>(JSContext*, wchar_t const*, unsigned int)|EXCEPTION_ACCESS_VIOLATION_READ (103 crashes)
     72% (74/103) vs.   5% (3782/69132) wrc@avast.com
          4% (4/103) vs.   1% (474/69132) 7.0.1474
          1% (1/103) vs.   0% (56/69132) 8.0.1482
         67% (69/103) vs.   2% (1334/69132) 8.0.1483
          0% (0/103) vs.   2% (1327/69132) 8.0.1489

Signature 	memcpy | js_NewStringCopyN<int>(JSContext*, wchar_t const*, unsigned int) More Reports Search
UUID	c036d7a1-9600-4165-a7d6-e4d182130526
Date Processed	2013-05-26 10:30:43
Uptime	54
Last Crash	4.9 weeks before submission
Install Age	11.6 hours since version was first installed.
Install Time	2013-05-25 22:52:53
Product	Firefox
Version	24.0a1
Build ID	20130525031005
Release Channel	nightly
OS	Windows NT
OS Version	6.2.9200
Build Architecture	x86
Build Architecture Info	GenuineIntel family 6 model 37 stepping 5
Crash Reason	EXCEPTION_ACCESS_VIOLATION_READ
Crash Address	0x18f6c524
App Notes 	
AdapterVendorID: 0x8086, AdapterDeviceID: 0x0046, AdapterSubsysID: 04871025, AdapterDriverVersion: 8.15.10.2858
D2D? D2D+ DWrite? DWrite+ D3D10 Layers? D3D10 Layers+ 
Processor Notes 	sp-processor02_phx1_mozilla_com_32086:2012
EMCheckCompatibility	True
Adapter Vendor ID	0x8086
Adapter Device ID	0x0046
Total Virtual Memory	4294836224
Available Virtual Memory	3765321728
System Memory Use Percentage	27
Available Page File	10432421888
Available Physical Memory	4448813056

Frame 	Module 	Signature 	Source
0 	msvcr100.dll 	memcpy 	f:\dd\vctools\crt_bld\SELF_X86\crt\src\INTEL\memcpy.asm:185
1 	mozjs.dll 	js_NewStringCopyN<1> 	js/src/jsstr.cpp:3620
2 	mozjs.dll 	js::ScriptSource::substring 	js/src/jsscript.cpp:1258
3 	mozjs.dll 	JSScript::sourceData 	js/src/jsscript.cpp:1180
4 	mozjs.dll 	js::FunctionToString 	js/src/jsfun.cpp:633
5 	mozjs.dll 	fun_toStringHelper 	js/src/jsfun.cpp:764
6 	mozjs.dll 	fun_toString 	js/src/jsfun.cpp:782
...

More reports at:
https://crash-stats.mozilla.com/report/list?signature=memcpy+|+js_NewStringCopyN%3Cint%3E%28JSContext*%2C+wchar_t+const*%2C+unsigned+int%29
(Assignee)

Updated

4 years ago
Assignee: general → nobody

Updated

3 years ago
Crash Signature: [@ memcpy | js_NewStringCopyN<int>(JSContext*, wchar_t const*, unsigned int)] [@ memcpy | js_NewStringCopyN(JSContext*, wchar_t const*, unsigned int) ] → [@ memcpy | js_NewStringCopyN<int>(JSContext*, wchar_t const*, unsigned int)] [@ memcpy | js_NewStringCopyN(JSContext*, wchar_t const*, unsigned int) ] [@ memcpy | js_NewStringCopyN<T>] [@ memcpy | js_NewStringCopyN ]
Closing because no crash reported since 12 weeks.
Status: NEW → RESOLVED
Last Resolved: a month ago
Resolution: --- → WONTFIX
You need to log in before you can comment on or make changes to this bug.