Bug 161899

Summary: Null-pointer dereference in WebCore::MediaPlayer::getStartDate
Product: WebKit Reporter: codecolorist
Component: MediaAssignee: Nobody <webkit-unassigned>
Status: RESOLVED DUPLICATE    
Severity: Normal    
Priority: P2    
Version: Safari Technology Preview   
Hardware: Unspecified   
OS: Unspecified   

codecolorist
Reported 2016-09-13 02:29:23 PDT
In webkit/Source/WebCore/html/HTMLMediaElement.cpp, the method HTMLMediaElement::getStartDate doesn't check if m_player is null: double HTMLMediaElement::getStartDate() const { return m_player->getStartDate().toDouble(); } So this simple one line javascript can crash the browser: document.createElement('video').getStartDate()
Attachments
codecolorist
Comment 1 2016-09-13 02:51:56 PDT
*** This bug has been marked as a duplicate of bug 16898 ***
Note You need to log in before you can comment on or make changes to this bug.