Closed Bug 1758302 Opened 4 years ago Closed 4 years ago

Crash and/or high memory on webmail site with very large message

Categories

(Firefox :: Untriaged, defect)

Firefox 97
defect

Tracking

()

RESOLVED INCOMPLETE

People

(Reporter: youngmis3r, Unassigned, NeedInfo)

Details

Attachments

(4 files)

User Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:97.0) Gecko/20100101 Firefox/97.0
Firefox for Android

Steps to reproduce:

Greetings!

I'm an amateur bug bounty hunter and a while back I found a bug on a site that allowed me to email a long string subject line to someone in order to bog down their inbox. When I tried a longer payload it caused firefox to crash repeatedly when visiting the site.

Actual results:

The long string caused firefox to crash repeatedly when visiting the site initially. Now it seems to cause a spike in CPU usage followed by a crash if it is caching the webpage for the first time.

Expected results:

I've attached the original proof of concept video from the original report to the site. I've checked the inbox on the site today and it still causes a crash when trying to cache the page for the first time. This behaviour only seems to be present on firefox, and may be worth looking into in order to avoid future exploitation. It worked on multiple windows devices as well as my android.

https://youtu.be/p93yucwAyZE Is the PoC from a few months ago.

When I visit the long string DoS site it causes a large memory spike. However, I just noticed that after leaving the site and closed the tab my memory usage continued being high (anywhere from 3000 to 5000 MB). It persists until the browser is closed. I attempted this on Chrome and it did not cause a memory spike. I've added 3 images showing this.

  1. Image 1, I visit example.com in firefox before visiting the long string DoS.
  2. Image 2, I visit the site where the long payload is placed.
  3. Image 3, I close out of the tab, but the excessive memory usage continues until I close out of firefox entirely.
Attached image Normal Memory Usage

Thanks for the report. Do you have a crash report for the crash that you saw? It should show up in about:crashes.

This sounds like something that would be good to fix, given that it isn't causing issues in other browsers, but there are unfortunately lots of ways to exhaust the resources in a browser, and the user can simply restart their browser after it crashes, so it isn't exactly a security bug.

Group: firefox-core-security
Summary: Potential Denial of Service Bug → Crash and/or high memory on webmail site with very large message

The Bugbug bot thinks this bug should belong to the 'Toolkit::Crash Reporting' component, and is moving the bug to that component. Please revert this change in case you think the bot is wrong.

Component: Untriaged → Crash Reporting
Product: Firefox → Toolkit

Unfortunately nothing is showing up in about:crashes, it's just a long string denial of service. For some reason I did notice that Chrome will render the subject line on the email and not cause the site to lag at all whereas Firefox will not render it and it lags immensely. I tried using the prebuilt debug browser but it causes that to crash 100% of the time and doesn't deliver an output. This could very well be intended behaviour given how lengthy the message is/how much a resource hog it is to load.

I've contacted the site owner as the message now permanently disables a person's inbox. Still pretty new to all this but I figured I'd mention it here just in case. I'll attach a photo of how the pages are being displayed differently between chrome and firefox.

Attached image render.png
Component: Crash Reporting → Untriaged
Product: Toolkit → Firefox

Hello! I have tried to reproduce the issue with Windows 10 with firefox 100.0a1(2022-03-30) unfortunately I wasn't able to reproduce the issue.
Could you please answer the following questions in order to further investigate this issue:

  1. Does this issue happen with a new profile? Here is a link on how to create one: https://support.mozilla.org/en-US/kb/profile-manager-create-remove-switch-firefox-profiles
  2. Does this issue happen in the latest nightly? Here is a link from where you can download it: https://www.mozilla.org/en-US/firefox/channel/desktop/
  3. Do you have any addons installed if so can you list them?
Flags: needinfo?(youngmis3r)

We'd love to investigate this further, but without usable STR or perhaps even an about:memory dump it doesn't seen actionable for now as it is not clear what isn't freeing memory or going O(n^2) trying to process things.

Status: UNCONFIRMED → RESOLVED
Closed: 4 years ago
Resolution: --- → INCOMPLETE
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Creator:
Created:
Updated:
Size: