pkgsrc/lang/spidermonkey52
maya 436119c28b spidermonkey52: backport patch for CVE-2018-12387
Don't inline push with more than 1 argument

A vulnerability where the JavaScript JIT compiler inlines Array.prototype.push with multiple arguments that results in the stack pointer being off by 8 bytes after a bailout. This leaks a memory address to the calling function which can be used as part of an exploit inside the sandboxed content process.

Bump PKGREVISION
2018-10-03 18:58:22 +00:00
..
patches spidermonkey52: backport patch for CVE-2018-12387 2018-10-03 18:58:22 +00:00
buildlink3.mk
DESCR
distinfo spidermonkey52: backport patch for CVE-2018-12387 2018-10-03 18:58:22 +00:00
hacks.mk TLS is broken on NetBSD aarch64, so force use of pthread_{set,get}specific 2018-08-01 09:32:27 +00:00
Makefile spidermonkey52: backport patch for CVE-2018-12387 2018-10-03 18:58:22 +00:00
PLIST - Fix for polkit and gjs 2018-05-16 11:36:36 +00:00
PLIST.Linux spidermonkey52: add linux specific plist file to fix install on linux. 2018-05-22 17:32:50 +00:00