Summary: | cross_fuzz WTF::Vector<...>::reserveCapacity DebugBreak (e59d9e1bc9ba856e181342fbfc4517c9) | ||||||
---|---|---|---|---|---|---|---|
Product: | WebKit | Reporter: | Berend-Jan Wever <skylined> | ||||
Component: | DOM | Assignee: | Nobody <webkit-unassigned> | ||||
Status: | RESOLVED WONTFIX | ||||||
Severity: | Normal | CC: | abarth, ap, eric, jay.bhaskar, lcamtuf | ||||
Priority: | P1 | ||||||
Version: | 528+ (Nightly build) | ||||||
Hardware: | PC | ||||||
OS: | Windows Vista | ||||||
URL: | http://code.google.com/p/chromium/issues/detail?id=50206 | ||||||
Bug Depends on: | |||||||
Bug Blocks: | 42959 | ||||||
Attachments: |
|
Description
Berend-Jan Wever
2010-07-27 04:31:48 PDT
I suspect that it's possible with message ports to get a renderer to crash. http://trac.webkit.org/browser/trunk/JavaScriptCore/wtf/Vector.h#L864 OOM => DebugBreak. News at 11. |