Bug 239154
Summary: | [CoreIPC][WebGL] Heap Buffer Overflow from CoreIPC WebGL MultiDraw* due to discarded firsts/counts length in favour of attacker controlled drawcount | ||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Product: | WebKit | Reporter: | John Cunningham <johncunningham> | ||||||||||||||
Component: | WebGL | Assignee: | Nobody <webkit-unassigned> | ||||||||||||||
Status: | RESOLVED FIXED | ||||||||||||||||
Severity: | Normal | CC: | bfulgham, cdumez, changseok, dino, esprehn+autocc, ews-feeder, ews-watchlist, gavin.p, gyuyoung.kim, kbr, kkinnunen, kondapallykalyan, webkit-bug-importer | ||||||||||||||
Priority: | P2 | Keywords: | InRadar | ||||||||||||||
Version: | WebKit Nightly Build | ||||||||||||||||
Hardware: | iPhone / iPad | ||||||||||||||||
OS: | Unspecified | ||||||||||||||||
Attachments: |
|
2022-04-12 13:47 PDT, John Cunningham
2022-04-13 18:55 PDT, John Cunningham
2022-04-13 20:19 PDT, John Cunningham
2022-04-13 20:22 PDT, John Cunningham
2022-04-20 11:33 PDT, John Cunningham
2022-04-20 11:50 PDT, John Cunningham