<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugs.webkit.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.4.1"
          urlbase="https://bugs.webkit.org/"
          
          maintainer="admin@webkit.org"
>

    <bug>
          <bug_id>158037</bug_id>
          <alias>CVE-2016-4761</alias>
          <creation_ts>2016-05-24 12:30:08 -0700</creation_ts>
          <short_desc>Fix use-after-free after r201318</short_desc>
          <delta_ts>2017-10-11 10:27:55 -0700</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>WebKit</product>
          <component>Bindings</component>
          <version>WebKit Nightly Build</version>
          <rep_platform>Unspecified</rep_platform>
          <op_sys>Unspecified</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords></keywords>
          <priority>P2</priority>
          <bug_severity>Normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Alex Christensen">achristensen</reporter>
          <assigned_to name="Nobody">webkit-unassigned</assigned_to>
          <cc>bfulgham</cc>
    
    <cc>cdumez</cc>
          

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>1195963</commentid>
    <comment_count>0</comment_count>
    <who name="Alex Christensen">achristensen</who>
    <bug_when>2016-05-24 12:30:08 -0700</bug_when>
    <thetext>Fix use-after-free after r201318</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1195970</commentid>
    <comment_count>1</comment_count>
      <attachid>279690</attachid>
    <who name="Alex Christensen">achristensen</who>
    <bug_when>2016-05-24 12:37:02 -0700</bug_when>
    <thetext>Created attachment 279690
Patch</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1195982</commentid>
    <comment_count>2</comment_count>
    <who name="Alex Christensen">achristensen</who>
    <bug_when>2016-05-24 13:01:02 -0700</bug_when>
    <thetext>http://trac.webkit.org/changeset/201345</thetext>
  </long_desc>
      
          <attachment
              isobsolete="0"
              ispatch="1"
              isprivate="0"
          >
            <attachid>279690</attachid>
            <date>2016-05-24 12:37:02 -0700</date>
            <delta_ts>2016-05-24 12:55:56 -0700</delta_ts>
            <desc>Patch</desc>
            <filename>bug-158037-20160524123808.patch</filename>
            <type>text/plain</type>
            <size>2940</size>
            <attacher name="Alex Christensen">achristensen</attacher>
            
              <data encoding="base64">SW5kZXg6IFNvdXJjZS9XZWJDb3JlL0NoYW5nZUxvZwo9PT09PT09PT09PT09PT09PT09PT09PT09
PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09Ci0tLSBTb3VyY2UvV2Vi
Q29yZS9DaGFuZ2VMb2cJKHJldmlzaW9uIDIwMTM0MikKKysrIFNvdXJjZS9XZWJDb3JlL0NoYW5n
ZUxvZwkod29ya2luZyBjb3B5KQpAQCAtMSwzICsxLDIwIEBACisyMDE2LTA1LTI0ICBBbGV4IENo
cmlzdGVuc2VuICA8YWNocmlzdGVuc2VuQHdlYmtpdC5vcmc+CisKKyAgICAgICAgRml4IHVzZS1h
ZnRlci1mcmVlIGFmdGVyIHIyMDEzMTgKKyAgICAgICAgaHR0cHM6Ly9idWdzLndlYmtpdC5vcmcv
c2hvd19idWcuY2dpP2lkPTE1ODAzNworICAgICAgICByZGFyOi8vcHJvYmxlbS8yNjQ0NjcyOQor
CisgICAgICAgIFJldmlld2VkIGJ5IE5PQk9EWSAoT09QUyEpLgorCisgICAgICAgIFRoaXMgZml4
ZXMgYSBjcmFzaCB3aGVuIHJ1bm5pbmcgZmFzdC9kb20vbmF2aWdhdGlvbi13aXRoLXNpZGVlZmZl
Y3RzLmh0bWwgd2l0aCBHdWFyZE1hbGxvYy4KKworICAgICAgICAqIGJpbmRpbmdzL3NjcmlwdHMv
Q29kZUdlbmVyYXRvckpTLnBtOgorICAgICAgICAoR2VuZXJhdGVJbXBsZW1lbnRhdGlvbik6Cisg
ICAgICAgICogYmluZGluZ3Mvc2NyaXB0cy90ZXN0L0pTL0pTVGVzdE9iai5jcHA6CisgICAgICAg
IChXZWJDb3JlOjpzZXRKU1Rlc3RPYmpQdXRGb3J3YXJkc051bGxhYmxlQXR0cmlidXRlKToKKyAg
ICAgICAgQ2hhbmdpbmcgUmVmUHRyPCR7dHlwZX0+IHRvIGF1dG8gY2F1c2VkIHRoZSB0eXBlIHRv
IHNvbWV0aW1lcyBiZSBhIHJhdyBwb2ludGVyLCB3aGljaCBkb2VzIG5vdCBrZWVwIHRoZSBvYmpl
Y3QgYWxpdmUuCisgICAgICAgIEluIHRoZSBjYXNlIG9mIEpTRG9jdW1lbnQuY3BwLCBmb3J3YXJk
ZWRJbXBsIHdhcyB3aGF0IERvY3VtZW50Ojpsb2NhdGlvbiByZXR1cm5lZCwgd2hpY2ggaXMgYSBM
b2NhdGlvbiogYW5kIG5vdCBhIFJlZlB0cjxMb2NhdGlvbj4uCisKIDIwMTYtMDUtMjQgIENocmlz
IER1bWV6ICA8Y2R1bWV6QGFwcGxlLmNvbT4KIAogICAgICAgICBVc2UgbGFtYmRhIGNhcHR1cmUg
d2l0aCBpbml0aWFsaXplciBpbnN0ZWFkIG9mIFN0cmluZ0NhcHR1cmUKSW5kZXg6IFNvdXJjZS9X
ZWJDb3JlL2JpbmRpbmdzL3NjcmlwdHMvQ29kZUdlbmVyYXRvckpTLnBtCj09PT09PT09PT09PT09
PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT0KLS0t
IFNvdXJjZS9XZWJDb3JlL2JpbmRpbmdzL3NjcmlwdHMvQ29kZUdlbmVyYXRvckpTLnBtCShyZXZp
c2lvbiAyMDEzMzYpCisrKyBTb3VyY2UvV2ViQ29yZS9iaW5kaW5ncy9zY3JpcHRzL0NvZGVHZW5l
cmF0b3JKUy5wbQkod29ya2luZyBjb3B5KQpAQCAtMjkxOSw3ICsyOTE5LDcgQEAgc3ViIEdlbmVy
YXRlSW1wbGVtZW50YXRpb24KICAgICAgICAgICAgICAgICAgICAgaWYgKCRwdXRGb3J3YXJkcykg
ewogICAgICAgICAgICAgICAgICAgICAgICAgbXkgJGltcGxHZXR0ZXJGdW5jdGlvbk5hbWUgPSAk
Y29kZUdlbmVyYXRvci0+V0tfbGNmaXJzdCgkYXR0cmlidXRlLT5zaWduYXR1cmUtPmV4dGVuZGVk
QXR0cmlidXRlcy0+eyJJbXBsZW1lbnRlZEFzIn0gfHwgJG5hbWUpOwogICAgICAgICAgICAgICAg
ICAgICAgICAgaWYgKCRhdHRyaWJ1dGUtPnNpZ25hdHVyZS0+aXNOdWxsYWJsZSkgewotICAgICAg
ICAgICAgICAgICAgICAgICAgICAgIHB1c2goQGltcGxDb250ZW50LCAiICAgIGF1dG8gZm9yd2Fy
ZGVkSW1wbCA9IGNhc3RlZFRoaXMtPndyYXBwZWQoKS4ke2ltcGxHZXR0ZXJGdW5jdGlvbk5hbWV9
KCk7XG4iKTsKKyAgICAgICAgICAgICAgICAgICAgICAgICAgICBwdXNoKEBpbXBsQ29udGVudCwg
IiAgICBSZWZQdHI8JHt0eXBlfT4gZm9yd2FyZGVkSW1wbCA9IGNhc3RlZFRoaXMtPndyYXBwZWQo
KS4ke2ltcGxHZXR0ZXJGdW5jdGlvbk5hbWV9KCk7XG4iKTsKICAgICAgICAgICAgICAgICAgICAg
ICAgICAgICBwdXNoKEBpbXBsQ29udGVudCwgIiAgICBpZiAoIWZvcndhcmRlZEltcGwpXG4iKTsK
ICAgICAgICAgICAgICAgICAgICAgICAgICAgICBwdXNoKEBpbXBsQ29udGVudCwgIiAgICAgICAg
cmV0dXJuIGZhbHNlO1xuIik7CiAgICAgICAgICAgICAgICAgICAgICAgICAgICAgcHVzaChAaW1w
bENvbnRlbnQsICIgICAgYXV0byYgaW1wbCA9ICpmb3J3YXJkZWRJbXBsO1xuIik7CkluZGV4OiBT
b3VyY2UvV2ViQ29yZS9iaW5kaW5ncy9zY3JpcHRzL3Rlc3QvSlMvSlNUZXN0T2JqLmNwcAo9PT09
PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09PT09
PT09PT09Ci0tLSBTb3VyY2UvV2ViQ29yZS9iaW5kaW5ncy9zY3JpcHRzL3Rlc3QvSlMvSlNUZXN0
T2JqLmNwcAkocmV2aXNpb24gMjAxMzM2KQorKysgU291cmNlL1dlYkNvcmUvYmluZGluZ3Mvc2Ny
aXB0cy90ZXN0L0pTL0pTVGVzdE9iai5jcHAJKHdvcmtpbmcgY29weSkKQEAgLTM5MzYsNyArMzkz
Niw3IEBAIGJvb2wgc2V0SlNUZXN0T2JqUHV0Rm9yd2FyZHNOdWxsYWJsZUF0dHIKICAgICBpZiAo
VU5MSUtFTFkoIWNhc3RlZFRoaXMpKSB7CiAgICAgICAgIHJldHVybiB0aHJvd1NldHRlclR5cGVF
cnJvcigqc3RhdGUsICJUZXN0T2JqIiwgInB1dEZvcndhcmRzTnVsbGFibGVBdHRyaWJ1dGUiKTsK
ICAgICB9Ci0gICAgYXV0byBmb3J3YXJkZWRJbXBsID0gY2FzdGVkVGhpcy0+d3JhcHBlZCgpLnB1
dEZvcndhcmRzTnVsbGFibGVBdHRyaWJ1dGUoKTsKKyAgICBSZWZQdHI8VGVzdE5vZGU+IGZvcndh
cmRlZEltcGwgPSBjYXN0ZWRUaGlzLT53cmFwcGVkKCkucHV0Rm9yd2FyZHNOdWxsYWJsZUF0dHJp
YnV0ZSgpOwogICAgIGlmICghZm9yd2FyZGVkSW1wbCkKICAgICAgICAgcmV0dXJuIGZhbHNlOwog
ICAgIGF1dG8mIGltcGwgPSAqZm9yd2FyZGVkSW1wbDsK
</data>
<flag name="review"
          id="303735"
          type_id="1"
          status="+"
          setter="beidson"
    />
          </attachment>
      

    </bug>

</bugzilla>