Last Comment Bug 439800 - (CVE-2008-2786) Crash when try to follow a link with a bad formated URL
(CVE-2008-2786)
: Crash when try to follow a link with a bad formated URL
Status: RESOLVED DUPLICATE of bug 402735
[sg:needinfo]
:
Product: Firefox
Classification: Client Software
Component: General (show other bugs)
: 3.0 Branch
: x86 Windows XP
: -- critical (vote)
: ---
Assigned To: Nobody; OK to take it and work on it
:
:
Mentors:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2008-06-17 19:16 PDT by pierre
Modified: 2009-02-08 23:38 PST (History)
5 users (show)
See Also:
Crash Signature:
(edit)
QA Whiteboard:
Iteration: ---
Points: ---
Has Regression Range: ---
Has STR: ---


Attachments
testcase, attached to the bug (262 bytes, text/html)
2008-06-18 04:01 PDT, Martijn Wargers [:mwargers] (not working for Mozilla)
no flags Details

Description pierre 2008-06-17 19:16:15 PDT
User-Agent:       Mozilla/5.0 (Windows; U; Windows NT 5.1; fr; rv:1.9) Gecko/2008052906 Firefox/3.0
Build Identifier: Mozilla/5.0 (Windows; U; Windows NT 5.1; fr; rv:1.9) Gecko/2008052906 Firefox/3.0

When try to follow a link like :

<a href="/http%3A%2F%2Fwww.proof-of-concept.fr%2Fpoc%2Fpersonnel%2FGuillaume.Hexapode%2Fnode310.html">
  test
</a>

Firefox crash.

I've no time to look over it, but seems a overflow.

Reproducible: Always

Steps to Reproduce:
1.create a html page with a link like :

<a href="/http%3A%2F%2Fwww.proof-of-concept.fr%2Fpoc%2Fpersonnel%2FGuillaume.Hexapode%2Fnode310.html">
  test
</a>

2. visit this page.

3. clic on the link
Actual Results:  
crash

Expected Results:  
not crash ?

I use Firefox 3 Realease
No toolbarn, no pluggins.
Comment 1 Martijn Wargers [:mwargers] (not working for Mozilla) 2008-06-18 02:51:38 PDT
You mean http://www.proof-of-concept.fr/poc/personnel/Guillaume.Hexapode/node310.html
?
I get a "La page est introuvable"
Comment 2 pierre 2008-06-18 03:04:18 PDT
<a href="http://www.proof-of-concept.fr/poc/personnel/Guillaume.Hexapode/node310.html">http://www.proof-of-concept.fr/poc/personnel/Guillaume.Hexapode/node310.html</a>
?
I get a &quot;La page est introuvable&quot;

----

You forget the slash in fornt of your URL.


Comment 3 Martijn Wargers [:mwargers] (not working for Mozilla) 2008-06-18 03:31:46 PDT
Which slash?
With http://www.proof-of-concept.fr/poc/personnel/Guillaume.Hexapode/node310.html/ , I still get a "page not found" error.
Comment 4 pierre 2008-06-18 03:44:31 PDT
URL must be :

/http%3A%2F%2Fwww.proof-of-concept.fr%2Fpoc%2Fpersonnel%2FGuillaume.Hexapode%2Fnode310.html

with / in front

This web page doesn't exist. It's just to show the problem
Comment 5 Martijn Wargers [:mwargers] (not working for Mozilla) 2008-06-18 04:01:55 PDT
Created attachment 325529 [details]
testcase, attached to the bug

Ah,ok, thanks. So your original code example is correct.
Comment 6 Martijn Wargers [:mwargers] (not working for Mozilla) 2008-06-18 04:04:47 PDT
This is worksforme.
Pierre, does the crash also happens in safe mode?
http://support.mozilla.com/en-US/kb/Safe+Mode
Or with a new, clean profile?
Comment 7 pierre 2008-06-18 04:18:45 PDT
Work in safe mode. I'll try to look from where can come.
Comment 8 Daniel Veditz [:dveditz] 2008-06-18 15:59:58 PDT
pierre: do you crash with the testcase Martijn attached? it's possible we're still not interpreting you correctly.
Comment 9 pierre 2008-06-18 18:40:55 PDT
Yes I crash with the testcase Martijn attached when I'm not in safe mode.

When I use safe mode, I don't crash.
Comment 10 Al Billings [:abillings] 2008-06-19 11:34:45 PDT
This WFM on the Mac. Martijn, did you try this on XP?
Comment 11 Martijn Wargers [:mwargers] (not working for Mozilla) 2008-06-19 15:00:33 PDT
I tried on Vista.
Pierre, can you find out if one of your extensions is causing this crash?
Comment 12 pierre 2008-06-19 17:39:10 PDT
I've test extension by extension.

And look like one of my extension is causing the crash :
Download accelerator plus ( http://www.speedbit.com/ ).

Sorry I don't take time to see where crash come from before.
Comment 13 Martijn Wargers [:mwargers] (not working for Mozilla) 2008-06-21 05:28:45 PDT
Pierre, thanks for finding out why you were crashing!

This looks like the same bug as bug 402735 to me.

*** This bug has been marked as a duplicate of bug 402735 ***

Note You need to log in before you can comment on or make changes to this bug.