pkgsrc/lang/spidermonkey52/patches
maya 436119c28b spidermonkey52: backport patch for CVE-2018-12387
Don't inline push with more than 1 argument

A vulnerability where the JavaScript JIT compiler inlines Array.prototype.push with multiple arguments that results in the stack pointer being off by 8 bytes after a bailout. This leaks a memory address to the calling function which can be used as part of an exploit inside the sandboxed content process.

Bump PKGREVISION
2018-10-03 18:58:22 +00:00
..
patch-build_moz.configure_init.configure
patch-config_gcc__hidden.h - Fix for polkit and gjs 2018-05-16 11:36:36 +00:00
patch-CVE-2018-12387 spidermonkey52: backport patch for CVE-2018-12387 2018-10-03 18:58:22 +00:00
patch-intl_icu_source_configure
patch-js_src_gc_Memory.cpp
patch-js_src_jsnativestack.cpp
patch-js_src_old-configure_in Fix patch. Thanks leot@! 2018-05-19 13:00:56 +00:00
patch-js_src_tests_update-test262.sh
patch-js_src_threading_posix_Thread.cpp
patch-js_src_wasm_WasmSignalHandlers.cpp
patch-memory_mozalloc_mozalloc__abort.cpp
patch-mfbt_Poison.cpp
patch-mfbt_tests_TestPoisonArea.cpp
patch-modules_fdlibm_src_math__private.h
patch-mozglue_build_moz.build - Fix for polkit and gjs 2018-05-16 11:36:36 +00:00
patch-python_mozbuild_mozbuild_backend_recursivemake.py - Fix for polkit and gjs 2018-05-16 11:36:36 +00:00
patch-python_mozbuild_mozbuild_configure_constants.py