StaticPopup taint from insecure (Set)AbandonQuest hooks #23


  • New
  • Defect
Open
Assigned to _ForgeUser44280
  • thisisdurcyn created this issue Dec 10, 2012

    12/10 22:43:14.017  Global variable SetAbandonQuest tainted by Ace3 - Interface\AddOns\Ace3\AceHook-3.0\AceHook-3.0.lua:245 hook()
    12/10 22:43:14.017      Interface\AddOns\Ace3\AceHook-3.0\AceHook-3.0.lua:286 Hook()
    12/10 22:43:14.017      Interface\AddOns\QuestHubber\QuestHubber.lua:284
    12/10 22:43:14.017      xpcall()
    12/10 22:43:14.017      safecall Dispatcher[1]:9
    12/10 22:43:14.017      Interface\AddOns\Ace3\AceAddon-3.0\AceAddon-3.0.lua:543 EnableAddon()
    12/10 22:43:14.017      Interface\AddOns\Ace3\AceAddon-3.0\AceAddon-3.0.lua:636
    12/10 22:43:14.017      LoadAddOn()
    12/10 22:43:14.017      Interface\FrameXML\UIParent.lua:299 UIParentLoadAddOn()
    12/10 22:43:14.017      Interface\FrameXML\UIParent.lua:322 CombatLog_LoadUI()
    12/10 22:43:14.017      Interface\FrameXML\UIParent.lua:692
    12/10 22:43:14.017  Global variable AbandonQuest tainted by Ace3 - Interface\AddOns\Ace3\AceHook-3.0\AceHook-3.0.lua:245 hook()
    12/10 22:43:14.017      Interface\AddOns\Ace3\AceHook-3.0\AceHook-3.0.lua:286 Hook()
    12/10 22:43:14.017      Interface\AddOns\QuestHubber\QuestHubber.lua:285
    12/10 22:43:14.017      xpcall()
    12/10 22:43:14.017      safecall Dispatcher[1]:9
    12/10 22:43:14.017      Interface\AddOns\Ace3\AceAddon-3.0\AceAddon-3.0.lua:543 EnableAddon()
    12/10 22:43:14.017      Interface\AddOns\Ace3\AceAddon-3.0\AceAddon-3.0.lua:636
    12/10 22:43:14.017      LoadAddOn()
    12/10 22:43:14.017      Interface\FrameXML\UIParent.lua:299 UIParentLoadAddOn()
    12/10 22:43:14.017      Interface\FrameXML\UIParent.lua:322 CombatLog_LoadUI()
    12/10 22:43:14.017      Interface\FrameXML\UIParent.lua:692
    12/10 23:39:08.877  Execution tainted by Ace3 while reading AbandonQuest - Interface\FrameXML\StaticPopup.lua:1958 OnAccept()
    12/10 23:39:08.877      Interface\FrameXML\StaticPopup.lua:3897 StaticPopup_OnClick()
    12/10 23:39:08.877      StaticPopup1Button1:OnClick()

    Which of course blocks talent functions.  Please see if you can use secure posthooks to accomplish whatever it is you're doing.

  • thisisdurcyn added the tags New Defect Dec 10, 2012

To post a comment, please login or register a new account.