Commit 2f92d22c authored by Dominik Bay's avatar Dominik Bay Committed by Pier Angelo Vendrame
Browse files

Bug 2066736 - Validate filter array lengths in FilePickerParent::RecvOpen. a=dmeehan

The loop in RecvOpen counts with aFilters.Length() but reads
aFilterNames[i]. If a content process sends the message with more filters
than filterNames, the read goes out of bounds and the parent process
crashes. So I added a check that both arrays have the same length.

Original Revision: https://phabricator.services.mozilla.com/D321511

Differential Revision: https://phabricator.services.mozilla.com/D321697
parent 25c303c6
Loading
Loading
Loading
Loading
+4 −0
Changes for dom/ipc/FilePickerParent.cpp: 4 added lines, 0 removed lines.
Original line number Diff line number Diff line
@@ -283,6 +283,10 @@ mozilla::ipc::IPCResult FilePickerParent::RecvOpen(
    return IPC_OK();
  }

  if (aFilters.Length() != aFilterNames.Length()) {
    return IPC_FAIL(this, "PFilePicker::Open filter arrays lengths mismatch");
  }

  mFilePicker->SetAddToRecentDocs(aAddToRecentDocs);

  for (uint32_t i = 0; i < aFilters.Length(); ++i) {