Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

List of known security problems with old SpiderMonkey code base? #499

Open
petterreinholdtsen opened this issue Jan 21, 2025 · 2 comments
Open

Comments

@petterreinholdtsen
Copy link

Is there a list of known security issues with the embedded SpiderMonkey code base used by ooline, ref https://github.com/OoliteProject/spidermonkey-ff4/ ? It seem to have been untouched for 8-12 years. I have been able to locate
https://security-tracker.debian.org/tracker/CVE-2019-11750 myself, but am unsure if there are others.

@AnotherCommander
Copy link
Member

I am not aware of any such list.

I am not sure if this would sufficiently cover your inquiry about security, but there is an old discussion from the time just before adopting the SpiderMonkey FF4 version we use now. Check out the posts by Jens and make sure to not miss the later ones too. The measures taken to minimize risks are also discussed (white listing of executable methods etc.).

Link to discussion: https://bugzilla.redhat.com/show_bug.cgi?id=459211

@petterreinholdtsen
Copy link
Author

petterreinholdtsen commented Jan 21, 2025 via email

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants