<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugs.webkit.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.4.1"
          urlbase="https://bugs.webkit.org/"
          
          maintainer="admin@webkit.org"
>

    <bug>
          <bug_id>60795</bug_id>
          
          <creation_ts>2011-05-13 13:28:22 -0700</creation_ts>
          <short_desc>REGRESSION (WebKit2): Crash due to heap corruption in old versions of VLC plugin when page has two or more plugin instances</short_desc>
          <delta_ts>2022-06-23 19:51:45 -0700</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>1</classification_id>
          <classification>Unclassified</classification>
          <product>WebKit</product>
          <component>Plug-ins</component>
          <version>528+ (Nightly build)</version>
          <rep_platform>Unspecified</rep_platform>
          <op_sys>Unspecified</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>WONTFIX</resolution>
          
          
          <bug_file_loc>data:text/html,&lt;embed type=&quot;application/x-vlc-plugin&quot;&gt;&lt;embed type=&quot;application/x-vlc-plugin&quot;&gt;</bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords>InRadar, PlatformOnly, Regression</keywords>
          <priority>P2</priority>
          <bug_severity>Normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          <blocked>46399</blocked>
          <everconfirmed>1</everconfirmed>
          <reporter name="Adam Roben (:aroben)">aroben</reporter>
          <assigned_to name="Nobody">webkit-unassigned</assigned_to>
          <cc>andersca</cc>
    
    <cc>bweinstein</cc>
    
    <cc>jhoneycutt</cc>
          

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>403795</commentid>
    <comment_count>0</comment_count>
    <who name="Adam Roben (:aroben)">aroben</who>
    <bug_when>2011-05-13 13:28:22 -0700</bug_when>
    <thetext>To reproduce:

1. Install VLC 0.6.8d from http://download.videolan.org/pub/videolan/vlc/0.8.6d/win32/vlc-0.8.6d-win32.exe
2. Go to data:text/html,&lt;embed type=&quot;application/x-vlc-plugin&quot;&gt;&lt;embed type=&quot;application/x-vlc-plugin&quot;&gt;
3. Reload the page until crash occurs

The crash is in free() inside VLC code. The bug happens only in WebKit2, not in WebKit1. It looks like this happens in Firefox and Chrome, too, but it&apos;s harder to detect there due to out-of-process plugins.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>403798</commentid>
    <comment_count>1</comment_count>
    <who name="Adam Roben (:aroben)">aroben</who>
    <bug_when>2011-05-13 13:29:08 -0700</bug_when>
    <thetext>WebKit1 works around this VLC bug using the PluginQuirkDontAllowMultipleInstances quirk.

Note that the crash does not occur with the most recent version of VLC, 1.1.9. I haven&apos;t tested any other versions.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>403802</commentid>
    <comment_count>2</comment_count>
    <who name="Adam Roben (:aroben)">aroben</who>
    <bug_when>2011-05-13 13:29:54 -0700</bug_when>
    <thetext>&lt;rdar://problem/9436117&gt;</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>1878094</commentid>
    <comment_count>3</comment_count>
    <who name="Alexey Proskuryakov">ap</who>
    <bug_when>2022-06-23 19:51:45 -0700</bug_when>
    <thetext>Plug-in support has been removed from WebKit.</thetext>
  </long_desc>
      
      

    </bug>

</bugzilla>