[tor-bugs] #16495 [Tor Browser]: Tor Browser 5.0a3 crashes with security level set to "High"

Tor Bug Tracker & Wiki blackhole at torproject.org
Tue Jul 21 19:58:59 UTC 2015


#16495: Tor Browser 5.0a3 crashes with security level set to "High"
-------------------------+-------------------------------------------------
     Reporter:  gk       |      Owner:  mcs
         Type:  defect   |     Status:  needs_review
     Priority:           |  Milestone:
  critical               |    Version:
    Component:  Tor      |   Keywords:  tbb-crash, TorBrowserTeam201507,
  Browser                |  tbb-5.0a4
   Resolution:           |  Parent ID:
Actual Points:           |
       Points:           |
-------------------------+-------------------------------------------------
Changes (by mcs):

 * status:  assigned => needs_review


Comment:

 Here is a revised patch that is ready for review:
 https://gitweb.torproject.org/user/brade/tor-
 browser.git/commit/?h=bug16495-02&id=9e59dae7fdb9527f688b03fa314e917712024d4b

 It fixes all of the crashes that were reported and adds protection in
 other places too.
 Unfortunately, it is difficult to be 100% certain that we found all the
 places where Bad Things can happen due to use of static_cast or negligence
 to check for failed QI's.  If we keep finding more crashes due to our SVG
 blocking patches, we may need to adopt a different approach (but hopefully
 this patch is sufficient).

 Once are happy with this for TB 5.0, we can rebase for TB 4.5.x if needed.

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/16495#comment:19>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list