[Webkit-unassigned] [Bug 80333] Crash in RenderLayer::scrollTo

bugzilla-daemon at webkit.org bugzilla-daemon at webkit.org
Wed Mar 7 13:10:58 PST 2012


Alexey Proskuryakov <ap at webkit.org> changed:

           What    |Removed                     |Added
            Summary|Crash while fuzzing.        |Crash in
                   |                            |RenderLayer::scrollTo
           Platform|Unspecified                 |All
         OS/Version|Unspecified                 |All
             Status|UNCONFIRMED                 |NEW
                 CC|                            |inferno at chromium.org,
                   |                            |macpherson at chromium.org,
                   |                            |simon.fraser at apple.com
     Ever Confirmed|0                           |1

--- Comment #3 from Alexey Proskuryakov <ap at webkit.org>  2012-03-07 13:10:58 PST ---
OK, looks like a NULL deference. And much like bug 66208 :(

With ToT, this freezes WebProcess or crashes with ASSERT_NOT_REACHED in CSS code, which may be a separate issue.

Configure bugmail: https://bugs.webkit.org/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are the assignee for the bug.

More information about the webkit-unassigned mailing list