Skip to content

Fail to throw a Type Error #93

Description

@sunlili

version: jsish 3.5.0
os: ubuntu 20.04

poc1:

var V0 = (Object . setPrototypeOf ( Object . prototype , Array . prototype ));
var V1 = ( ( Number . NaN != new Object ( ) ) !== true ) ;

poc2:

const V5 = ( Object . setPrototypeOf ( Object . prototype , Array . prototype ) ) ;
let V6 = ( new RegExp ( 'new value' ) . source ) ;

output:
segment fault caused by OOM

My fuzzer finds those crashes, which caused by the same bug. Object.setPrototypeOf(Object.prototype, Array.prototype) makes the prototype chain loop. Object.prototype should be a immutable prototype exotic object. So, jsish should throw a TypeError when js code sets the prototype of the builtin Object.

ISec Lab.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions