Comment #15 on issue 248 by [email protected]: local var with same name as function
http://code.google.com/p/google-caja/issues/detail?id=248

I think we have to always rename the catch variables, otherwise you can access an arbitrary global using catch. this in itself is not a full breach, but could lead to a full breach.

Reply via email to