[Webkit-unassigned] [Bug 29313] Fix hard-to-reproduce crash in HTMLTokenizer by avoiding a rare fastRealloc edge case

bugzilla-daemon at webkit.org bugzilla-daemon at webkit.org
Wed Sep 16 14:14:26 PDT 2009


https://bugs.webkit.org/show_bug.cgi?id=29313


Dimitri Glazkov (Google) <dglazkov at chromium.org> changed:

           What    |Removed                     |Added
----------------------------------------------------------------------------
  Attachment #39660|                            |review?
               Flag|                            |




--- Comment #1 from Dimitri Glazkov (Google) <dglazkov at chromium.org>  2009-09-16 14:14:25 PDT ---
Created an attachment (id=39660)
 --> (https://bugs.webkit.org/attachment.cgi?id=39660)
Fix HTMLTokenizer crash, v1.

 WebCore/ChangeLog              |   15 +++++++++++++++
 WebCore/html/HTMLTokenizer.cpp |    8 ++++++++
 2 files changed, 23 insertions(+), 0 deletions(-)

-- 
Configure bugmail: https://bugs.webkit.org/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are the assignee for the bug.



More information about the webkit-unassigned mailing list