WebKit Bugzilla
New
Browse
Log In
×
Sign in with GitHub
or
Remember my login
Create Account
·
Forgot Password
Forgotten password account recovery
RESOLVED DUPLICATE of
bug 111179
48895
gif image buffer crash in cairo platform
https://bugs.webkit.org/show_bug.cgi?id=48895
Summary
gif image buffer crash in cairo platform
partin
Reported
2010-11-02 18:58:44 PDT
In ImageDecoderCairo.cpp: RGBA32Buffer::asNewNativeImage() call cairo_image_surface_create_for_data(). cairo_image_surface_create_for_data() do not copy the data to use,but hold the pointer to access.That will cause the crash happen. GIFImageDecoder::frameCount() will call m_frameBufferCache.resize(reader.images_count),that will cause the data of the cairo_image_surface_create_for_data() holding be invalid.
Attachments
Add attachment
proposed patch, testcase, etc.
Ed Catmur
Comment 1
2014-04-09 21:07:11 PDT
Duplicate of
bug 16200
.
Michael Catanzaro
Comment 2
2017-03-06 10:34:48 PST
*** This bug has been marked as a duplicate of
bug 111179
***
Note
You need to
log in
before you can comment on or make changes to this bug.
Top of Page
Format For Printing
XML
Clone This Bug