DOS: some extensions (noscript/adblock/adblockplus/ietab) break js runaway detection

RESOLVED INCOMPLETE

Status

()

Core
DOM: Core & HTML
RESOLVED INCOMPLETE
12 years ago
8 years ago

People

(Reporter: tsattler, Unassigned)

Tracking

1.8 Branch
x86
Linux
Points:
---

Firefox Tracking Flags

(Not tracked)

Details

(URL)

(Reporter)

Description

12 years ago
User-Agent:       Mozilla/5.0 (X11; U; Linux i686; de; rv:1.8.0.4) Gecko/20060508 Firefox/1.5.0.4
Build Identifier: Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.8b2) Gecko/20050702

Some very popular extensions break detection of JaveScript runaways:
 - noscript-1.1.4.1
 - adblock-0.5.3.042
 - adblockPlus-0.7.0.2
 - ie-tab-1.0.9

The given code iterates over the existing images, cloning them and adding them to the document. It's a bug in the script not to end but the browser should detect that.

Reproducible: Always

Steps to Reproduce:
1. install at least one of noscript-1.1.4.1, adblock-0.5.3.042, adblockPlus-0.7.0.2, ie-tab-1.0.9
2. allow JavaScript for the given URL
3. open the given URL

Actual Results:  
100% CPU, mozilla/firefox hangs

Expected Results:  
detect runaway

The problem occures only with images and only if I clone existing ones. Creating new images in an endless loop causes no hang.

Comment 1

12 years ago
i don't think dos's should be classified, that won't get them fixed faster.
Assignee: general → general
Component: General → DOM: HTML
Product: Mozilla Application Suite → Core
QA Contact: general → ian
Version: unspecified → 1.8 Branch
Group: security

Updated

10 years ago
Component: DOM: HTML → DOM: Core & HTML
QA Contact: ian → general
URL is no longer available. Please reopen with a test case if this still happens in Gecko 2.0.
Assignee: general → nobody
Status: UNCONFIRMED → RESOLVED
Last Resolved: 8 years ago
Resolution: --- → INCOMPLETE
You need to log in before you can comment on or make changes to this bug.