Konqueror crashes when visiting page

Bug #214866 reported by AleksanderAdamowski
10
Affects Status Importance Assigned to Milestone
KDE Base
Invalid
High
kdebase (Ubuntu)
Fix Released
Undecided
Unassigned

Bug Description

On Ubuntu Gutsy, konqueror 4:3.5.8-0ubuntu2.2 crashes when visiting this page:

http://magicgarden.sourceforge.net/?q=node/26

One can navigate to that page from this page by clicking the "render with leaves" image:

http://magicgarden.sourceforge.net/?q=image/tid/2

Crash results in the following stacktrace (only top 14 frames, see the attachment for full stacktrace):

Using host libthread_db library "/lib/tls/i686/cmov/libthread_db.so.1".
[Thread debugging using libthread_db enabled]
[New Thread -1233430320 (LWP 8812)]
[KCrash handler]
#6 0xb5d56dc7 in khtml::RenderBlock::addChildToFlow (this=0x95487d0,
    newChild=0x955e280, beforeChild=0x9548854)
    at /build/buildd/kdelibs-3.5.8/./khtml/rendering/render_block.cpp:372
#7 0xb5d052a6 in khtml::RenderFlow::addChild (this=0x95487d0,
    newChild=0x955e280, beforeChild=0x9548854)
    at /build/buildd/kdelibs-3.5.8/./khtml/rendering/render_flow.cpp:128
#8 0xb5d56c4f in khtml::RenderBlock::addChildToFlow (this=0x95485d4,
    newChild=0x955e280, beforeChild=0x9548854)
    at /build/buildd/kdelibs-3.5.8/./khtml/rendering/render_block.cpp:298
#9 0xb5d052a6 in khtml::RenderFlow::addChild (this=0x95485d4,
    newChild=0x955e280, beforeChild=0x9548854)
    at /build/buildd/kdelibs-3.5.8/./khtml/rendering/render_flow.cpp:128
#10 0xb5c9e249 in DOM::NodeImpl::createRendererIfNeeded (this=0xa8f0100)
    at /build/buildd/kdelibs-3.5.8/./khtml/xml/dom_nodeimpl.cpp:938
#11 0xb5c9e272 in DOM::ElementImpl::attach (this=0xa8f0100)
    at /build/buildd/kdelibs-3.5.8/./khtml/xml/dom_elementimpl.cpp:536
#12 0xb5ca6859 in DOM::NodeBaseImpl::insertBefore (this=0xa8eea78,
    newChild=0xa8f0100, refChild=0xa8f22e8, exceptioncode=@0xbf949288)
    at /build/buildd/kdelibs-3.5.8/./khtml/xml/dom_nodeimpl.cpp:1086
#13 0xb5e74121 in DOM::Node::insertBefore (this=0xbf949370,
    newChild=@0xbf9493d8, refChild=@0xbf9493d0)
    at /build/buildd/kdelibs-3.5.8/./khtml/dom/dom_node.cpp:262
#14 0xb5e0055e in KJS::DOMNodeProtoFunc::tryCall (this=0x93892c0,
    exec=0xbf949964, thisObj=@0xbf949720, args=@0xbf949714)
    at /build/buildd/kdelibs-3.5.8/./khtml/ecma/kjs_dom.cpp:586

Revision history for this message
AleksanderAdamowski (aadamowski) wrote :
Revision history for this message
Marcus Asshauer (mcas) wrote :

Thank you for reporting this bug. I can reproduce this with hardy and
konqueror:
  Installiert:4:3.5.9-0ubuntu6
  Mögliche Pakete:4:3.5.9-0ubuntu6
  Versions-Tabelle:
 *** 4:3.5.9-0ubuntu6 0
        500 http://ports.ubuntu.com hardy/main Packages
        100 /var/lib/dpkg/status

Changed in kdebase:
status: New → Confirmed
Revision history for this message
Ralph Janke (txwikinger) wrote :

There are no security or vulnerability issues, removed the flag

Changed in kdebase:
status: Unknown → New
Changed in kdebase:
status: New → Invalid
Revision history for this message
Jonathan Thomas (echidnaman) wrote :

Fixed in Konqueror 4.0.83 in Intrepid Ibex. (Kubuntu 8.10)
Thanks for the bug report!

Changed in kdebase:
status: Confirmed → Fix Released
Changed in kdebase:
status: Invalid → Unknown
Changed in kdebase:
importance: Unknown → High
status: Unknown → Invalid
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.