|
WebKit contains a bad cast flaw in the 'SelectElement::setSelectedIndex' function [WebCore/dom/SelectElement.cpp]. The issue is triggered when firing an onchange event that changes the select from a menu list to a list box. With a specially crafted web page, a context-dependent attacker can corrupt memory to cause a denial of service or potentially execute arbitrary code.
|