DescriptionSimple Cache: validate lengths before allocations.
This bug was most unfortunate. A corrupt entry could cause Chrome to
crash when opening it, without removing the entry. Not a good loop to
be in. Now we are much more careful with casts around the data coming
from disk to confirm sanity before proceeding.
R=juliatuttle@chromium.org
BUG=541720
Review-Url: https://codereview.chromium.org/2086053003
Cr-Commit-Position: refs/heads/master@{#408134}
(cherry picked from commit bf840cc6c21c5a5b6e95d120e5493e0a7eb61498)
Committed: https://chromium.googlesource.com/chromium/src/+/4cf894119c534fbf3fce69ef3d684cfc16b59fbf
Patch Set 1 #
Messages
Total messages: 2 (1 generated)
|