Closed
Bug 965904
Opened 11 years ago
Closed 11 years ago
Fix array-related rooting hazards in the browser
Categories
(Core :: JavaScript Engine, defect)
Core
JavaScript Engine
Tracking
()
RESOLVED
FIXED
mozilla29
| Tracking | Status | |
|---|---|---|
| firefox28 | --- | unaffected |
| firefox29 | --- | fixed |
| firefox-esr24 | --- | unaffected |
People
(Reporter: jonco, Assigned: jonco)
References
(Blocks 1 open bug)
Details
(Keywords: csectype-uaf, regression, sec-high)
Attachments
(1 file)
|
7.50 KB,
patch
|
terrence
:
review+
|
Details | Diff | Splinter Review |
Looking through the new unsafe reference warnings produced in the wake of bug 963738 found 6 new rooting hazards.
Fixed by using AutoValueVector to hold and root the contents of the arrays.
Attachment #8368059 -
Flags: review?(terrence)
| Assignee | ||
Comment 1•11 years ago
|
||
Try run here: https://tbpl.mozilla.org/?tree=Try&rev=2503ec4e1c21
Comment 2•11 years ago
|
||
Exact rooting is trunk-only.
status-firefox28:
--- → unaffected
status-firefox29:
--- → affected
Comment 3•11 years ago
|
||
Comment on attachment 8368059 [details] [diff] [review]
fix-unrooted-arrays
Review of attachment 8368059 [details] [diff] [review]:
-----------------------------------------------------------------
Great! r=me. Lets get this in as-is right now and do a follow-up to remove the resize and use inline slots once we've exposed that template parameter.
Attachment #8368059 -
Flags: review?(terrence) → review+
Updated•11 years ago
|
Whiteboard: [leave open
| Assignee | ||
Comment 4•11 years ago
|
||
Comment 5•11 years ago
|
||
| Assignee | ||
Comment 6•11 years ago
|
||
Followup is happening in bug 965830, so closing this as fixed.
Status: NEW → RESOLVED
Closed: 11 years ago
Resolution: --- → FIXED
Whiteboard: [leave open
Updated•11 years ago
|
Target Milestone: --- → mozilla29
Updated•11 years ago
|
status-firefox-esr24:
--- → unaffected
Updated•10 years ago
|
Group: core-security
You need to log in
before you can comment on or make changes to this bug.
Description
•