Closed Bug 1558322 Opened 5 years ago Closed 5 years ago

AddressSanitizer: global-buffer-overflow [@ nsContentUtils::ShouldResistFingerprinting] with READ of size 4

Categories

(Core :: Graphics, defect)

x86_64
Windows
defect
Not set
minor

Tracking

()

RESOLVED DUPLICATE of bug 1557409
Tracking Status
firefox69 --- fixed

People

(Reporter: decoder, Unassigned)

References

Details

(4 keywords, Whiteboard: [adv-main69-])

Attachments

(1 file)

The attached crash information was submitted via the ASan Nightly Reporter on mozilla-central-asan-nightly revision 69.0a1-20190607220156-https://hg.mozilla.org/mozilla-central/rev/522a2bc06f9e5d0767bb3f2e127cc21eeaeb8a78.

For detailed crash information, see attachment.

Attached file Detailed Crash Information (deleted) —
Flags: sec-bounty?

Weird. I doubt this has anything to do with Resist Fingerprinting; it seems like the principal passed in got messed up somehow.

Group: core-security → gfx-core-security

Ehsan, is this a dupe of bug 1557409? Thanks.

Flags: needinfo?(ehsan)

I'll just mark it sec-high for now.

(In reply to Andrew McCreight [:mccr8] from comment #4)

Ehsan, is this a dupe of bug 1557409? Thanks.

Yes exactly. It's amazing a real user has hit it in the wild! Was there a crash url submitted alongside the crash report?

Status: NEW → RESOLVED
Closed: 5 years ago
Flags: needinfo?(ehsan)
Resolution: --- → DUPLICATE

(In reply to :Ehsan Akhgari from comment #6)

Yes exactly. It's amazing a real user has hit it in the wild! Was there a crash url submitted alongside the crash report?

Maybe decoder knows. I would guess not, but I'm not sure.

Flags: needinfo?(choller)

(In reply to :Ehsan Akhgari from comment #6)

Was there a crash url submitted alongside the crash report?

No, ASan Nightly does not collect crash URLs.

Flags: needinfo?(choller)
Flags: sec-bounty? → sec-bounty-
Whiteboard: [adv-main69-]

This is OffscreenCanvas, which is not yet a supported configuration.

Severity: critical → minor
Group: gfx-core-security
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: