[Webkit-unassigned] [Bug 109220] [Chromium] Fix use after free in ContextMenuClientImpl.cpp

bugzilla-daemon at webkit.org bugzilla-daemon at webkit.org
Thu Feb 7 15:50:57 PST 2013


https://bugs.webkit.org/show_bug.cgi?id=109220


Tony Chang <tony at chromium.org> changed:

           What    |Removed                     |Added
----------------------------------------------------------------------------
 Attachment #187154|review?                     |review-
               Flag|                            |




--- Comment #2 from Tony Chang <tony at chromium.org>  2013-02-07 15:53:06 PST ---
(From update of attachment 187154)
View in context: https://bugs.webkit.org/attachment.cgi?id=187154&action=review

> Source/WebKit/chromium/ChangeLog:8
> +
> +        * src/ContextMenuClientImpl.cpp:

Please provide more information here.  At a minimum, how people are triggering the crash and why this is the right fix.  It's not clear to me why this would fix a crash.  It would also be OK to link to the chromium bug.

Do you know if this is a recent regression?  It would be nice to know when this crash was introduced.

-- 
Configure bugmail: https://bugs.webkit.org/userprefs.cgi?tab=email
------- You are receiving this mail because: -------
You are the assignee for the bug.


More information about the webkit-unassigned mailing list