mirror of
git://source.winehq.org/git/wine.git
synced 2024-10-31 12:54:13 +00:00
2173cac68e
`ref` can be negative in case it refers to an argument. Even though scope != frame->base_scope would rule this out (because only base scopes have args), it was checked *after* the memory access, which would read out of bounds memory first. This didn't appear as an issue in practice since it's using the heap pool, so there's probably valid memory before it, but it's still wrong. Signed-off-by: Gabriel Ivăncescu <gabrielopcode@gmail.com> |
||
---|---|---|
.. | ||
tests | ||
activex.c | ||
array.c | ||
bool.c | ||
cc_parser.y | ||
compile.c | ||
date.c | ||
decode.c | ||
dispex.c | ||
engine.c | ||
engine.h | ||
enumerator.c | ||
error.c | ||
function.c | ||
global.c | ||
jscript.c | ||
jscript.h | ||
jscript.rc | ||
jscript.rgs | ||
jscript.spec | ||
jscript_classes.idl | ||
jscript_main.c | ||
jsglobal.idl | ||
jsglobal_dispid.h | ||
json.c | ||
jsregexp.c | ||
jsstr.c | ||
jsstr.h | ||
jsutils.c | ||
jsval.h | ||
lex.c | ||
Makefile.in | ||
math.c | ||
number.c | ||
object.c | ||
parser.h | ||
parser.y | ||
regexp.c | ||
regexp.h | ||
resource.h | ||
set.c | ||
string.c | ||
vbarray.c |