+++ This bug was initially created as a clone of Bug #213237 +++ Description of problem: Mozilla Firefox is prone to a DoS within its javascript Range object. In a special condition, a NULL Pointer Deference occur and Firefox crashes. Refer to advisory text or attached testcase for details. Version-Release number of selected component (if applicable): 1.5.0.7 -- Additional comment from lkundrak on 2006-10-31 07:53 EST -- Created an attachment (id=139850) Firefox 1.5.0.7 crash testcase -- Additional comment from lkundrak on 2006-10-31 08:00 EST -- (From update of attachment 139850 [details]) I set the MIME type of the patch to text/plain, for obvious reason.
Created attachment 139851 [details] Firefox 1.5.0.7 crash testcase
this bug is still present in Firefox 1.5.0.8
this bug is present in Firefox 2.0 too
This bug has been fixed in firefox-1.5.0.10-1.fc6 update released for Fedora Core 6.
This bug has also been fixed in firefox-2.0.0.2-1.fc7