Closed Bug 1232295 Opened 9 years ago Closed 9 years ago

Fix HTMLDocument.open's signature

Categories

(Core :: DOM: Core & HTML, defect)

defect
Not set
normal

Tracking

()

RESOLVED FIXED
Tracking Status
firefox45 --- wontfix
firefox46 --- fixed
firefox-esr45 --- wontfix

People

(Reporter: Ms2ger, Assigned: Ms2ger)

References

(Depends on 1 open bug)

Details

(Keywords: sec-moderate, Whiteboard: [post-critsmash-triage][adv-main46+])

Attachments

(1 file)

Not sure how bad this is, but it triggers the assertion in AssertReturnTypeMatchesJitinfo (null instead of object).
Attached patch Patch v1 (deleted) — Splinter Review
Attachment #8697998 - Flags: review?(khuey)
Comment on attachment 8697998 [details] [diff] [review] Patch v1 Review of attachment 8697998 [details] [diff] [review]: ----------------------------------------------------------------- A test?
Attachment #8697998 - Flags: review?(khuey) → review+
The way I found this was due to the popup blocker being enabled; I'll try to find a way to trigger it with it disabled (like we do in tests).
Group: core-security → dom-core-security
Summary: Fix HTMLElement#open's signature. → Fix HTMLDocument.open's signature.
Group: dom-core-security → core-security-release
Depends on: 1239351
Flags: qe-verify-
Whiteboard: [post-critsmash-triage]
Whiteboard: [post-critsmash-triage] → [post-critsmash-triage][adv-main46+]
Alias: CVE-2016-2815
Summary: Fix HTMLDocument.open's signature. → Fix HTMLDocument.open's signature
Alias: CVE-2016-2815
Group: core-security-release
Component: DOM → DOM: Core & HTML
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: