mirror of
https://repo.dactyloidae.xyz/Dactyloidae/UXP.git
synced 2026-09-21 15:57:31 +09:00
Bug 1333038 - Use 'modern' pointers to fix crash due to nsMsgLineStreamBuffer object being deleted while still in use.
Suspected "use after free" in nsMsgLineStreamBuffer::ReadNextLine() leading to crash since object may be destroyed while still in use on another thread. Tag #1273
This commit is contained in:
parent
37c62668cb
commit
14590876b2
13 changed files with 14 additions and 26 deletions
|
|
@ -50,8 +50,6 @@ PRLogModuleInfo *MAILBOX;
|
|||
nsMailboxProtocol::nsMailboxProtocol(nsIURI * aURI)
|
||||
: nsMsgProtocol(aURI)
|
||||
{
|
||||
m_lineStreamBuffer =nullptr;
|
||||
|
||||
// initialize the pr log if it hasn't been initialiezed already
|
||||
if (!MAILBOX)
|
||||
MAILBOX = PR_NewLogModule("MAILBOX");
|
||||
|
|
@ -59,8 +57,6 @@ nsMailboxProtocol::nsMailboxProtocol(nsIURI * aURI)
|
|||
|
||||
nsMailboxProtocol::~nsMailboxProtocol()
|
||||
{
|
||||
// free our local state
|
||||
delete m_lineStreamBuffer;
|
||||
}
|
||||
|
||||
nsresult nsMailboxProtocol::OpenMultipleMsgTransport(uint64_t offset, int32_t size)
|
||||
|
|
|
|||
|
|
@ -74,7 +74,7 @@ private:
|
|||
nsCOMPtr<nsIStreamListener> m_mailboxParser;
|
||||
|
||||
// Local state for the current operation
|
||||
nsMsgLineStreamBuffer * m_lineStreamBuffer; // used to efficiently extract lines from the incoming data stream
|
||||
RefPtr<nsMsgLineStreamBuffer> m_lineStreamBuffer; // used to efficiently extract lines from the incoming data stream
|
||||
|
||||
// Generic state information -- What state are we in? What state do we want to go to
|
||||
// after the next response? What was the last response code? etc.
|
||||
|
|
|
|||
|
|
@ -451,7 +451,6 @@ nsPop3Protocol::nsPop3Protocol(nsIURI* aURL)
|
|||
m_totalFolderSize(0),
|
||||
m_totalDownloadSize(0),
|
||||
m_totalBytesReceived(0),
|
||||
m_lineStreamBuffer(nullptr),
|
||||
m_pop3ConData(nullptr)
|
||||
{
|
||||
}
|
||||
|
|
@ -590,9 +589,6 @@ void nsPop3Protocol::Cleanup()
|
|||
FreeMsgInfo();
|
||||
PR_Free(m_pop3ConData->only_uidl);
|
||||
PR_Free(m_pop3ConData);
|
||||
|
||||
delete m_lineStreamBuffer;
|
||||
m_lineStreamBuffer = nullptr;
|
||||
}
|
||||
|
||||
void nsPop3Protocol::SetCapFlag(uint32_t flag)
|
||||
|
|
|
|||
|
|
@ -318,7 +318,7 @@ private:
|
|||
nsCOMPtr<nsIPop3Sink> m_nsIPop3Sink;
|
||||
nsCOMPtr<nsIPop3IncomingServer> m_pop3Server;
|
||||
|
||||
nsMsgLineStreamBuffer * m_lineStreamBuffer; // used to efficiently extract lines from the incoming data stream
|
||||
RefPtr<nsMsgLineStreamBuffer> m_lineStreamBuffer; // used to efficiently extract lines from the incoming data stream
|
||||
Pop3ConData* m_pop3ConData;
|
||||
void FreeMsgInfo();
|
||||
void Abort();
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue