My favorites | Sign in
Google
                
New issue | Search
for
| Advanced search | Search tips
Issue 49: SetWindow doesn't set window_
2 people starred this issue and may be notified of changes. Back to list
Status:  Accepted
Owner:  nfulla...@google.com
Security-Contest
Type-Defect


Sign in to add a comment
 
Reported by chris.rohlf, Mar 10, 2009
TEAM CJETM
Affected OS: Linux, OSX, Windows
Tested Browser: Firefox 3.0.6
Nacl Version nacl_linux_0.1_38_2009_02_11.tgz

The function NPError NPModule::SetWindow(NPWindow* window) takes a
window->width and window->height from attacker controllable HTML. An
attacker can cause this function prematurely return 0, which leaves window_
set to NULL. See the readme.txt for more information.
CJETM-3.tar.gz
2.5 KB   Download
Comment 1 by nativeclient.admin, Mar 12, 2009
Verified as an issue.
Status: Accepted
Owner: nfulla...@google.com
Labels: Type-Defect
Comment 2 by bradnel...@google.com, Dec 03, 2009
(No comment was entered for this change.)
Owner: nfulla...@google.com
Sign in to add a comment