Closed Bug 1674248 Opened 4 years ago Closed 11 months ago

DOS of browser across restarts or a DOS requiring reboot of user’s computer when import passwords from another browser

Categories

(Firefox :: Migration, defect, P3)

Firefox 82
defect

Tracking

()

RESOLVED INCOMPLETE

People

(Reporter: odayjava, Unassigned)

Details

User Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.111 Safari/537.36

Steps to reproduce:

I found the password field for saved login not have limitation length ,and when add long length password that lead to DOS of browser and maybe lead to restart of user computer .

1-Add text in below file as password for login account on chrome browser .

https://drive.google.com/file/d/1tLKaR6a0LvEaK3SHeY5dIQDHPQjFAtAf/view?usp=sharing

2-In firefox browser ,go to import data and setting

3-Import data from chrome browser and then in firefox go to saved login account in step #1

4-As you can see ,the browser is crash and there is memory loss .

Hi Dexter32,

is the text 364762 charactes long? Please attach crash id from about:crashes. Also share your about:support data please.

I'm not able to reproduce in windows 10 pro, nightly 84.0a1 (2020-11-02) (64-bit), beta 83.0b7 (64-bit) and release 82.0 (it gets slow, and unresponsive, for some seconds, and then it successfully imports the saved passwords)

Setting a component for this in order to get the dev team involved.
(If the team feels it's an incorrect one please feel free to change it to a more appropriate one.)

Best regards,
Clara

Component: Untriaged → Migration
Flags: needinfo?(odayjava)
Severity: -- → S4
Priority: -- → P3
Flags: sec-bounty?
Flags: sec-bounty? → sec-bounty-

A needinfo is requested from the reporter, however, the reporter is inactive on Bugzilla. Closing the bug as incomplete.

For more information, please visit BugBot documentation.

Status: UNCONFIRMED → RESOLVED
Closed: 11 months ago
Flags: needinfo?(odayjava)
Resolution: --- → INCOMPLETE
You need to log in before you can comment on or make changes to this bug.