Summary: | DOM modification causes stack exhaustion (exact cause unknown) | ||
---|---|---|---|
Product: | WebKit | Reporter: | Berend-Jan Wever <skylined> |
Component: | New Bugs | Assignee: | Nobody <webkit-unassigned> |
Status: | RESOLVED FIXED | ||
Severity: | Critical | CC: | bfulgham, mitz |
Priority: | P1 | Keywords: | InRadar |
Version: | 525.x (Safari 3.1) | ||
Hardware: | PC | ||
OS: | Windows Vista | ||
URL: | http://skypher.com/SkyLined/Repro/Safari/Stack%20exhaustion%20Unknown/repro.html |
Description
Berend-Jan Wever
2008-06-12 04:16:13 PDT
(In reply to comment #0) OOOPS. I copy+pasted the wrong code (see bug 19516). This is the real repro code for this case: <BODY onload="go()"><SCRIPT> function go() { oStrike=document.createElement('b'); oStrike.innerHTML='<object><table></table><colGroup></colGroup></object>'; document.body.parentElement.appendChild(oStrike); } </SCRIPT></BODY> Changing priority and security flag I cannot reproduce in r35011. I think this bug was fixed along with bug 15919 in <http://trac.webkit.org/changeset/34692>. |