Open
Bug 1227357
Opened 9 years ago
Updated 2 years ago
Firefox crash using window fatigue
Categories
(Core :: DOM: Core & HTML, defect)
Tracking
()
UNCONFIRMED
People
(Reporter: qab, Unassigned)
References
Details
(Keywords: crash, csectype-dos, testcase, Whiteboard: [sg:dos])
Attachments
(4 files)
User Agent: Mozilla/5.0 (Windows NT 6.3; WOW64; rv:42.0) Gecko/20100101 Firefox/42.0 Build ID: 20151029151421 Steps to reproduce: Based on an existing report of a hang: https://bugzilla.mozilla.org/show_bug.cgi?id=1226990 Except this time FF42 crashes instead of hanging. Run 'ff-hang.html' and press button Actual results: After a few minutes of freeze, firefox crashes Expected results: No crash
Reporter | ||
Comment 1•9 years ago
|
||
Stacktrace of crash. Note: crash reporter does not open.
Reporter | ||
Comment 2•9 years ago
|
||
Seems like when I tested this again, the crash reporter did open up, odd. https://crash-stats.mozilla.com/report/index/bp-3397992e-c463-42ef-bf32-3caf32151124
Reporter | ||
Comment 3•9 years ago
|
||
Updated•9 years ago
|
Group: firefox-core-security
Component: Untriaged → DOM
Product: Firefox → Core
Whiteboard: [sg:dos]
Reporter | ||
Comment 5•9 years ago
|
||
I assume this is unexploitable?
Comment 6•9 years ago
|
||
It looks like a safe out of memory crash.
Reporter | ||
Comment 7•9 years ago
|
||
(In reply to Andrew McCreight [:mccr8] from comment #6) > It looks like a safe out of memory crash. Ah I see. I have a third case (using the same click bug) which results in what seems like a completely empty firefox window (view attached screenshot) could that be indicative of exploitability. Note I cant reproduce it when I have windbg running.
Flags: needinfo?(continuation)
Comment 8•9 years ago
|
||
An empty window may just be another sign of running out of memory, or some kind of hang.
Flags: needinfo?(continuation)
Assignee | ||
Updated•5 years ago
|
Component: DOM → DOM: Core & HTML
Updated•2 years ago
|
Severity: normal → S3
You need to log in
before you can comment on or make changes to this bug.
Description
•