See http://code.google.com/p/chromium/issues/detail?id=68268 Open 0.html attached to the bug report.
Created attachment 78662 [details] Patch
Comment on attachment 78662 [details] Patch View in context: https://bugs.webkit.org/attachment.cgi?id=78662&action=review > Source/WebCore/ChangeLog:11 > + weird position and a crash will result for documents containing Could you explain what is "weird position" concretely and why it causes a crash concretely please?
Created attachment 78789 [details] Revised ChangeLog
Thank you for the review. Updated the ChangeLog. Does it look better? (In reply to comment #2) > (From update of attachment 78662 [details]) > View in context: https://bugs.webkit.org/attachment.cgi?id=78662&action=review > > > Source/WebCore/ChangeLog:11 > > + weird position and a crash will result for documents containing > > Could you explain what is "weird position" concretely and why it causes a crash concretely please?
(In reply to comment #4) > Updated the ChangeLog. Does it look better? Does it mean nextObj can be NULL?
Yes, it can be null and then the crash results. (In reply to comment #5) > (In reply to comment #4) > > Updated the ChangeLog. Does it look better? > > Does it mean nextObj can be NULL?
Comment on attachment 78789 [details] Revised ChangeLog ok, I understand.
Comment on attachment 78789 [details] Revised ChangeLog Thank you for the review.
Committed r76201: <http://trac.webkit.org/changeset/76201>