Closed Bug 861472 Opened 12 years ago Closed 11 years ago

WebVTT use after free [mozilla::dom::FragmentOrElement::Release]

Categories

(Core :: Audio/Video, defect)

Other Branch
x86
macOS
defect
Not set
normal

Tracking

()

RESOLVED WORKSFORME
Tracking Status
firefox21 --- unaffected
firefox22 --- unaffected
firefox23 --- unaffected
firefox24 - disabled
firefox25 --- disabled
firefox26 --- disabled
firefox27 --- disabled
firefox-esr17 --- unaffected
b2g18 --- unaffected

People

(Reporter: rforbes, Assigned: reyre)

References

Details

(5 keywords)

Attachments

(2 files)

Attached file testcase (deleted) —
use peach I found the included use after free error. I have included the test case and the callstack.
Attached file callstack (deleted) —
Blocks: 833385
Assigning to rillian (for triage and possible reassignment)
Assignee: nobody → giles
The plan is to land this disabled, so I'm just going to mark it disabled for 23.
Ralph, What is the status here? This landed for 24 and is disabled from what we can see. Can we get this fixed?
Flags: needinfo?(giles)
I can look into if you don't have time Ralph?
Thanks Rick. If you could take this I'd appreciate it. Should be easier to address now that the code is in-tree. Are you able to reproduce with m-c now?
Flags: needinfo?(giles)
Assignee: giles → rick.eyre
I can't reproduce this while testing on Fedora with an ASAN build.
I haven't been able to reproduce it on osx 10.8 or linux x64 with ASan -- But unfortunately there are a lot of other ASan problems on the mac which might be hiding it (the malloc/delete new/free mixup stuff)
I'm getting those as well. Hopefully, that's not hiding it.
What rev was this done against? We're no longer using the integration branch on github. We're now working off moz-central and all the code to test this is in there now.
rforbes, could you please check m-c and see if this issue is still present in the landed code?
Flags: needinfo?(rforbes)
Given this is disabled on nightly, not tracking it.Please renominate once this code is enabled and if the bug is still unfixed.
Status: NEW → RESOLVED
Closed: 11 years ago
Resolution: --- → WONTFIX
Status: RESOLVED → REOPENED
Resolution: WONTFIX → ---
Reproduction check no longer necessary; removing needinfo.
Flags: needinfo?(rforbes)
This is not reproducible anymore. It involved the old WebVTT parser which is not anymore in our code base.
Status: REOPENED → RESOLVED
Closed: 11 years ago11 years ago
Resolution: --- → FIXED
Resolution: FIXED → WORKSFORME
Group: core-security → core-security-release
Group: core-security-release
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: