Bug 1333038 - Use 'modern' pointers to fix crash due to nsMsgLineStreamBuffer object being deleted while still in use.

Suspected "use after free" in nsMsgLineStreamBuffer::ReadNextLine() leading to crash since object may be destroyed while still in use on another thread.

Tag #1273
This commit is contained in:
Matt A. Tobin 2019-11-10 21:59:52 -05:00 committed by Roy Tam
commit 14590876b2
13 changed files with 14 additions and 26 deletions

View file

@ -236,7 +236,6 @@ nsSmtpProtocol::~nsSmtpProtocol()
{
// free our local state
PR_Free(m_dataBuf);
delete m_lineStreamBuffer;
}
void nsSmtpProtocol::Initialize(nsIURI * aURL)

View file

@ -143,7 +143,7 @@ private:
int32_t m_previousResponseCode;
int32_t m_continuationResponse;
nsCString m_responseText; /* text returned from Smtp server */
nsMsgLineStreamBuffer *m_lineStreamBuffer; // used to efficiently extract lines from the incoming data stream
RefPtr<nsMsgLineStreamBuffer> m_lineStreamBuffer; // used to efficiently extract lines from the incoming data stream
nsTArray<nsCString> m_addresses;
uint32_t m_addressesLeft;