Changes between Initial Version and Version 1 of Ticket #26705, comment 4


Ignore:
Timestamp:
Jul 27, 2018, 2:20:32 PM (15 months ago)
Author:
gk
Comment:

Legend:

Unmodified
Added
Removed
Modified
  • Ticket #26705, comment 4

    initial v1  
    1 So, it seems both examples are more or less copy-and-pasted: the first example code from https://www.exploit-db.com/exploits/41660/ aka https://bugzilla.mozilla.org/show_bug.cgi?id=1340138 and the second one from http://www.signalsec.com/publications/UseAfterFree-Exploiting.pdf. The former got fixes a while ago and the latter seemed to affect IE 11, which is why neither crashes Tor Browser. Thus, closing as invalid.
     1So, it seems both examples are more or less copy-and-pasted: the first example code from https://www.exploit-db.com/exploits/41660/ aka https://bugzilla.mozilla.org/show_bug.cgi?id=1340138 and the second one from http://www.signalsec.com/publications/UseAfterFree-Exploiting.pdf. The former got fixed a while ago and the latter seemed to affect IE 11, which is why neither crashes Tor Browser. Thus, closing as invalid.