Bug 84648
Summary: | Failure to allocate ArrayStorage in emit_op_new_array leads to poisonous JSArray | ||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
Product: | WebKit | Reporter: | Mark Hahnenberg <mhahnenberg> | ||||||||||
Component: | JavaScriptCore | Assignee: | Mark Hahnenberg <mhahnenberg> | ||||||||||
Status: | RESOLVED FIXED | ||||||||||||
Severity: | Normal | CC: | fpizlo, ggaren, rafaelw | ||||||||||
Priority: | P2 | ||||||||||||
Version: | 528+ (Nightly build) | ||||||||||||
Hardware: | Unspecified | ||||||||||||
OS: | Unspecified | ||||||||||||
Attachments: |
|
2012-04-23 20:19 PDT, Mark Hahnenberg
2012-04-24 09:52 PDT, Mark Hahnenberg
2012-04-24 11:18 PDT, Mark Hahnenberg
2012-05-10 10:04 PDT, Rafael Weinstein