fix cve-2010-4205 (backported by Michael Gilbert):
authorinferno@chromium.org <inferno@chromium.org@268f45cc-cd09-0410-ab3c-d52691b4dbfc>
Tue, 26 Oct 2010 18:55:10 +0000 (18:55 +0000)
committerMichael Gilbert <michael.s.gilbert@gmail.com>
Wed, 13 Apr 2011 23:24:25 +0000 (19:24 -0400)
commit3373ecf1d263e7fc5b463bf8ffcc30a91c1b0188
tree5231823b367eeb32039721c55c6ea85b3db78abe
parent867a239a844a69310b4cfa4b08531bc9d8a6f3fc
fix cve-2010-4205 (backported by Michael Gilbert):

2010-10-26  Abhishek Arya  <inferno@chromium.org>

        Reviewed by Dimitri Glazkov.

        Added checks to ensure that events types are right before casting.
        https://bugs.webkit.org/show_bug.cgi?id=48345

        * html/ImageDocument.cpp:
        (WebCore::ImageEventListener::handleEvent):
        * inspector/InspectorDOMStorageResource.cpp:
        (WebCore::InspectorDOMStorageResource::handleEvent):

git-svn-id: http://svn.webkit.org/repository/webkit/trunk@70550 268f45cc-cd09-0410-ab3c-d52691b4dbfc
WebCore/inspector/InspectorDOMStorageResource.cpp
WebCore/loader/ImageDocument.cpp