Closed
Bug 382700
Opened 18 years ago
Closed 18 years ago
Unsafe DOM mutation events in object frame.
Categories
(Core :: DOM: Events, defect)
Tracking
()
RESOLVED
FIXED
People
(Reporter: vladimir.sukhoy, Unassigned)
References
Details
(4 keywords, Whiteboard: [sg:dupe 382681] keep private until 355548 is fixed)
Attachments
(1 file)
1.53 KB,
application/xhtml+xml
|
Details |
Using DOM mutation events it is possible to crash the browser or make the UI unresponsive.
Reporter | ||
Comment 1•18 years ago
|
||
See also bug 382568, bug 382681, bug 382700, bug 355548;
Here it is nsObjectFrame::CreateDefaultFrames that is vulnerable (does child manipulations which fire events and the JavaScript being invoked in the middle of frame code may do some damage).
Updated•18 years ago
|
Status: NEW → RESOLVED
Closed: 18 years ago
Resolution: --- → FIXED
Updated•18 years ago
|
Keywords: fixed1.8.0.5 → fixed1.8.1.5
Updated•18 years ago
|
Whiteboard: [sg:dupe 382681]
Comment 3•18 years ago
|
||
No hang or crash using Thunderbird version 1.5.0.13 (20070809) with JS enabled. Replacing fixed1.5.0.13 keyword with verified1.5.0.13.
Keywords: fixed1.8.0.13 → verified1.8.0.13
Updated•18 years ago
|
Flags: in-testsuite?
Whiteboard: [sg:dupe 382681] → [sg:dupe 382681] keep private until 355548 is fixed
Updated•12 years ago
|
Group: core-security
You need to log in
before you can comment on or make changes to this bug.
Description
•