I'll mark PDT+ to get on PDT radar.
Whiteboard: [PDT+] → [PDT+]; critical for 0.9.2
we need a good fix for this as soon as we can get it.
adding brendan and jst in case they can help.
Status: NEW → ASSIGNED
Whiteboard: [PDT+]; critical for 0.9.2 → [PDT+]; critical for 0.9.2; Have fix
jesse, can you review the patch?
Great catch! r/sr=vidur for J-F's fix. Calls to eval() and new Function() might be other places where similar patterns could exist.
eval, Script or new Script or Script.prototype.compile, Function or new Function, are all callable ase setTimeout("...", t) is -- they all take a string and compile and possibly execute it. Beware. firstname.lastname@example.org on the patch. /be
Fix checked in the branch, still need to check it in the trunk.
Whiteboard: [PDT+]; critical for 0.9.2; Have fix → [PDT+]; critical for 0.9.2; Fixed in the branch
Fixed in the trunk too.
Status: ASSIGNED → RESOLVED
Last Resolved: 18 years ago
Resolution: --- → FIXED
JFD, How do I verify this bug?
verified based on comments above trunk builds: 2001070206-win98, mac, 2001062906 linux Branch builds: 2001070206 win98, mac, linux.
Status: RESOLVED → VERIFIED
*** Bug 86613 has been marked as a duplicate of this bug. ***
Whiteboard: [PDT+]; critical for 0.9.2; Fixed in the branch → [PDT+]; critical for 0.9.2; Fixed in the branch; security
You need to log in before you can comment on or make changes to this bug.