Closed Bug 623378 Opened 14 years ago Closed 14 years ago

Firefox 4.0b9pre crash in [@ js::RegExpStatics::updateFromMatch(JSContext*, JSLinearString*, int*, unsigned int) ]

Categories

(Core :: JavaScript Engine, defect)

x86
Windows XP
defect
Not set
critical

Tracking

()

RESOLVED DUPLICATE of bug 606882
Tracking Status
blocking2.0 --- betaN+

People

(Reporter: marcia, Assigned: luke)

References

()

Details

(Keywords: crash, testcase, Whiteboard: [sg:critical?][hardblocker])

Crash Data

Attachments

(1 file)

Spinoff of Bug 595351 which was requested during Critsmash triage since it has a test case and it reproducible. See that bug for the reproducible testcase. Frame Module Signature [Expand] Source 0 mozjs.dll js::RegExpStatics::updateFromMatch js/src/jsregexp.h:188 1 mozjs.dll js::RegExp::executeInternal js/src/jsregexpinlines.h:351
Keywords: crash, testcase
Whiteboard: [sg:critical?]
Attached file testcase
copying testcase from the other bug where it's a private attachment that can't be seen by folks CC'd here.
who can take?
Assignee: general → lw
This might be a dup of bug 606882.
blocking2.0: --- → ?
Depends on: 606882
blocking2.0: ? → betaN+
Whiteboard: [sg:critical?] → [sg:critical?][hardblocker]
Confirmed fixed in a build that has fix for bug 606882.
Status: NEW → RESOLVED
Closed: 14 years ago
Resolution: --- → DUPLICATE
Crash Signature: [@ js::RegExpStatics::updateFromMatch(JSContext*, JSLinearString*, int*, unsigned int) ]
Group: core-security
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: