Type confusion in Indexed Database Manager
- July 2, 2015
- Paul Bandha
- Firefox, Firefox ESR, Firefox OS, SeaMonkey
- Fixed in
- Firefox 39
- Firefox ESR 31.8
- Firefox ESR 38.1
- Firefox OS 2.2
- SeaMonkey 2.35
Security researcher Paul Bandha reported a type confusion
error where part of
IDBDatabase is read by the Indexed Database
Manager and incorrectly used as a pointer when it shouldn't be used as such.
This leads to memory corruption and the possibility of an exploitable crash.