Bug 131137 - Crash when a function is constructed with the string "})({"
Summary: Crash when a function is constructed with the string "})({"
Status: NEW
Alias: None
Product: WebKit
Classification: Unclassified
Component: JavaScriptCore (show other bugs)
Version: 528+ (Nightly build)
Hardware: Macintosh OS X 10.9
: P2 Normal
Assignee: Nobody
URL:
Keywords:
Depends on:
Blocks:
 
Reported: 2014-04-02 16:17 PDT by webkit-bugs
Modified: 2014-08-15 13:59 PDT (History)
3 users (show)

See Also:


Attachments
A simple page that will crash the Safari web process. (58 bytes, text/plain)
2014-04-02 16:17 PDT, webkit-bugs
no flags Details

Note You need to log in before you can comment on or make changes to this bug.
Description webkit-bugs 2014-04-02 16:17:20 PDT
Created attachment 228440 [details]
A simple page that will crash the Safari web process.

When using the Function constructor to create a function with the string "})({", the invoking process will crash.  When using a string such as "})str({", an error is thrown instead. Changing it to  "});str({" will again cause a crash.
Comment 1 Mark S. Miller 2014-08-14 14:18:34 PDT
Is this a duplicate of https://bugs.webkit.org/show_bug.cgi?id=106160 ?