Closed
Bug 306782
Opened 19 years ago
Closed 19 years ago
[@ nsCSSFrameConstructor::GetFloatContainingBlock], [@ 0x4e800020] and other addresses
Categories
(Core :: Layout, defect)
Tracking
()
RESOLVED
DUPLICATE
of bug 265367
People
(Reporter: jruderman, Unassigned)
References
Details
(Keywords: crash, Whiteboard: [sg:dupe 265267] wait for 306663 to be opened)
Crash Data
Mozilla/5.0 (Macintosh; U; PPC Mac OS X Mach-O; en-US; rv:1.8b4) Gecko/20050901
Firefox/1.0+ crashes with the following testcase. Trunk does not. I think this
is an exploitable crash.
Reporter | ||
Comment 1•19 years ago
|
||
Crash reports for this testcase: TB8952610X, TB8952630Q
Crash reports with similar JavaScript used as a bookmarklet on various pages:
TB8922738K, TB8923005W, TB8923133W (from bug 306663).
Reporter | ||
Comment 2•19 years ago
|
||
Steps to reproduce:
1. Load the testcase.
2. Watch for about 3 seconds.
Result: Firefox crashes.
Reporter | ||
Comment 3•19 years ago
|
||
No crash with a Gecko 1.8 branch hourly. Fixed by the patch for bug 265367.
Reporter | ||
Comment 4•19 years ago
|
||
*** Bug 306787 has been marked as a duplicate of this bug. ***
Reporter | ||
Comment 5•19 years ago
|
||
*** Bug 306789 has been marked as a duplicate of this bug. ***
Reporter | ||
Comment 6•19 years ago
|
||
*** Bug 306798 has been marked as a duplicate of this bug. ***
Reporter | ||
Comment 7•19 years ago
|
||
I'm marking this as a dup of a public bug, but this bug should remain
security-sensitive until we decide to make the JavaScript code from bug 306663
public.
*** This bug has been marked as a duplicate of 265367 ***
Status: NEW → RESOLVED
Closed: 19 years ago
Resolution: --- → DUPLICATE
Updated•19 years ago
|
Whiteboard: [sg:dupe 265267] wait for 306663 to be opened
Updated•18 years ago
|
Group: security
Assignee | ||
Updated•13 years ago
|
Crash Signature: [@ nsCSSFrameConstructor::GetFloatContainingBlock]
[@ 0x4e800020]
You need to log in
before you can comment on or make changes to this bug.
Description
•