blob: 9f8596adc93b5c45d969ce56e05a5146df60e552 (
plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
|
/* -*- indent-tabs-mode: nil; js-indent-level: 2 -*- */
/* This Source Code Form is subject to the terms of the Mozilla Public
* License, v. 2.0. If a copy of the MPL was not distributed with this
* file, You can obtain one at http://mozilla.org/MPL/2.0/. */
//-----------------------------------------------------------------------------
var BUGNUMBER = 390597;
var summary = 'watch point + eval-as-setter allows access to dead JSStackFrame';
var actual = 'No Crash';
var expect = 'No Crash';
//-----------------------------------------------------------------------------
test();
//-----------------------------------------------------------------------------
function test()
{
enterFunc ('test');
printBugNumber(BUGNUMBER);
printStatus (summary);
function exploit() {
try
{
var obj = this, args = null;
obj.__defineSetter__("evil", eval);
obj.watch("evil", function() { return "args = arguments;"; });
obj.evil = null;
eval("print(args[0]);");
}
catch(ex)
{
print('Caught ' + ex);
}
}
exploit();
reportCompare(expect, actual, summary);
exitFunc ('test');
}
|