Closed Bug 457851 Opened 16 years ago Closed 16 years ago

Code in an html page instantly crashes Firefox.

Categories

(Core :: DOM: Core & HTML, defect)

1.9.0 Branch
x86
Windows XP
defect
Not set
critical

Tracking

()

VERIFIED DUPLICATE of bug 457543

People

(Reporter: reelix, Unassigned)

Details

(Keywords: crash, testcase)

Attachments

(1 file)

User-Agent:       Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.0.3) Gecko/2008092417 Firefox/3.0.3 (.NET CLR 3.5.30729)
Build Identifier: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.9.0.3) Gecko/2008092417 Firefox/3.0.3 (.NET CLR 3.5.30729)

I specifically crafted URL will cause Firefox to crash, displaying a Fatal Error Screen.

Version Affected: 3.0.1, 3.0.2, 3.0.3

Reproducible: Always

Steps to Reproduce:
1.) Go to http://www.reelix.za.net/crashFirefox301.html
Actual Results:  
Firefox Crashes, displaying a Fatal Error Message

Expected Results:  
Firefox shouldnt crash.
The attached page contains the relevant Crash-Code
Confirming with FF3.0.3

0  	xul.dll  	nsContentUtils::GetAccelKeyCandidates  	 mozilla/content/base/src/nsContentUtils.cpp:4111
1 	xul.dll 	nsCOMPtr_base::assign_from_qi 	nsCOMPtr.cpp:98
2 	xul.dll 	nsXBLKeyEventHandler::HandleEvent 	mozilla/content/xbl/src/nsXBLEventHandler.cpp:171
Status: UNCONFIRMED → NEW
Component: General → DOM
Ever confirmed: true
Keywords: crash, testcase
Product: Firefox → Core
QA Contact: general → general
Version: unspecified → 1.9.0 Branch
This doesn't crash in 3.1 builds.  On mozilla-central:
9-15 crashes
9-16 ok

There were a few private security bug changes on that day so I'd guess it's one of them. And I guess that change will make it into 3.0.4.  I think I know which change it was but it might be better to leave it vague.
It's fixed on trunk and will be fixed in 1.9.0.4 (Firefox 3.0.4).
Status: NEW → RESOLVED
Closed: 16 years ago
Resolution: --- → DUPLICATE
verified, thanks Mats
Status: RESOLVED → VERIFIED
Component: DOM → DOM: Core & HTML
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Creator:
Created:
Updated:
Size: