[Webkit-unassigned] [Bug 24172] Reproducible crash in CSSParser::parseFillImage copying contents of this page

bugzilla-daemon at webkit.org bugzilla-daemon at webkit.org
Wed Feb 25 14:23:48 PST 2009


https://bugs.webkit.org/show_bug.cgi?id=24172





------- Comment #1 from bdakin at apple.com  2009-02-25 14:23 PDT -------
Created an attachment (id=27984)
 --> (https://bugs.webkit.org/attachment.cgi?id=27984&action=view)
Reduction

Here is a reduction. To reproduce the crash, load the page in tip of tree
WebKit. Press Command-A to select all. Press Command-C to copy. Then you should
crash.

This is clearly a null-dereference. I am going to upload a null-check patch
momentarily.


-- 
Configure bugmail: https://bugs.webkit.org/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are the assignee for the bug, or are watching the assignee.



More information about the webkit-unassigned mailing list