Opened 5 years ago

Last modified 20 months ago

#12950 new task

Backport Windows ASLR forcing patch

Reported by: mikeperry Owned by: tbb-team
Priority: Medium Milestone:
Component: Applications/Tor Browser Version:
Severity: Normal Keywords: tbb-security
Cc: Actual Points:
Parent ID: Points:
Reviewer: Sponsor:

Description

Mozilla implemented a hack for forcing ASLR on DLLs that do not support it. They opted to land it in FF32 instead of FF31ESR. We should backport this patch:
https://bugzilla.mozilla.org/show_bug.cgi?id=677797

Child Tickets

Change History (8)

comment:1 Changed 5 years ago by mikeperry

Parent ID: #10065

comment:2 in reply to:  description Changed 5 years ago by gk

Replying to mikeperry:

Mozilla implemented a hack for forcing ASLR on DLLs that do not support it. They opted to land it in FF32 instead of FF31ESR. We should backport this patch:
https://bugzilla.mozilla.org/show_bug.cgi?id=677797

Hmm, this patch got backed out due to some issues (crashes) almost three years ago and did not re-land yet. So, nothing to backport :). Or did you have in mind of enhancing the proposed patch so that it fits into ESR 31 and get that one merged upstream?

comment:3 Changed 5 years ago by mikeperry

Keywords: tbb-security added; ff31-esr removed
Priority: majornormal

comment:4 Changed 5 years ago by mikeperry

Parent ID: #10065

comment:5 Changed 4 years ago by evilpie

Sorry, wrong issue #12523

Last edited 4 years ago by evilpie (previous) (diff)

comment:6 Changed 4 years ago by gk

Keywords: tbb-hardening added

comment:7 Changed 4 years ago by gk

Keywords: tbb-hardened added; tbb-hardening removed

comment:8 Changed 20 months ago by gk

Keywords: tbb-hardened removed
Severity: Normal
Note: See TracTickets for help on using tickets.