Last Comment Bug 444075 - XPCNativeWrapper pollution using chrome XBL
: XPCNativeWrapper pollution using chrome XBL
Status: VERIFIED FIXED
: [sg:critical] fixed by 441087
: verified1.8.1.17, verified1.9.0.2, verified1.9.1
Product: Core
Classification: Components
Component: XPConnect
: unspecified
: x86 Windows XP
: P1 normal (vote)
: ---
Assigned To: Blake Kaplan (:mrbkap)
: xpconnect
:
:
:
  Show dependency treegraph
 
Reported: 2008-07-08 03:17 PDT by moz_bug_r_a4
Modified: 2009-02-05 22:33 PST (History)
10 users (show)
benjamin: blocking1.9.1+
samuel.sidler+old: blocking1.9.0.2+
dveditz: blocking1.8.1.17+
dveditz: wanted1.8.1.x+
asac: blocking1.8.0.next+
See Also:
Crash Signature:


Attachments

Summon comment box

Description moz_bug_r_a4 2008-07-08 03:17:26 PDT
It's possible to modify an implicit XPCNativeWrapper within a chrome XBL method
without using eval-like methods nor __defineGetter__.  (See also the second
paragraph of bug 387390 comment #21.)
Comment 2 Blake Kaplan (:mrbkap) 2008-07-24 13:34:20 PDT
The patch in bug 441087 fixes this.
Comment 3 Samuel Sidler (old account; do not CC) 2008-08-15 17:10:36 PDT
Fixed by bug 441087.
Comment 4 Blake Kaplan (:mrbkap) 2008-08-18 14:52:30 PDT
Marking fixed to follow bug 441087.
Comment 5 moz_bug_r_a4 2008-08-27 04:23:03 PDT
This bug is not fixed on fx-2.0.0.17pre-2008-08-26-03.  See also bug 441087
comment #29.
Comment 6 Samuel Sidler (old account; do not CC) 2008-08-27 13:12:12 PDT
Fix for 441087 was checked in.
Comment 7 Stephen Donner [:stephend] 2008-08-29 18:38:01 PDT
With the testcase in comment 0, I can very easily reproduce in 2.0.0.16 (Mozilla/5.0 (Windows; U; Windows NT 6.0; en-US; rv:1.8.1.16) Gecko/20080702 Firefox/2.0.0.16), but not in 2.0.0.17 (Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.1.17) Gecko/20080829 Firefox/2.0.0.17).

Verified FIXED; replacing fixed1.8.1.17 with verified1.8.1.17.
Comment 8 Stephen Donner [:stephend] 2008-08-29 18:38:37 PDT
Meant to type "comment 1," sigh...
Comment 9 Al Billings [:abillings] 2008-09-05 17:05:09 PDT
Verified for 1.9.0.2 with Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10.5; en-US; rv:1.9.0.2) Gecko/2008090212 Firefox/3.0.2.
Comment 10 Tony Chung [:tchung] 2009-02-05 22:33:09 PST
Verified fix on Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10.5; en-US; rv:1.9.1b3pre) Gecko/20090205 Shiretoko/3.1b3pre Ubiquity/0.1.5 
and Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10.5; en-US; rv:1.9.2a1pre) Gecko/20090205 Minefield/3.2a1pre

Note You need to log in before you can comment on or make changes to this bug.