The default bug view has changed. See this FAQ.
Bug 439800 (CVE-2008-2786)

Crash when try to follow a link with a bad formated URL

RESOLVED DUPLICATE of bug 402735

Status

()

Firefox
General
--
critical
RESOLVED DUPLICATE of bug 402735
9 years ago
8 years ago

People

(Reporter: pierre, Unassigned)

Tracking

3.0 Branch
x86
Windows XP
Points:
---

Firefox Tracking Flags

(Not tracked)

Details

(Whiteboard: [sg:needinfo])

Attachments

(1 attachment)

(Reporter)

Description

9 years ago
User-Agent:       Mozilla/5.0 (Windows; U; Windows NT 5.1; fr; rv:1.9) Gecko/2008052906 Firefox/3.0
Build Identifier: Mozilla/5.0 (Windows; U; Windows NT 5.1; fr; rv:1.9) Gecko/2008052906 Firefox/3.0

When try to follow a link like :

<a href="/http%3A%2F%2Fwww.proof-of-concept.fr%2Fpoc%2Fpersonnel%2FGuillaume.Hexapode%2Fnode310.html">
  test
</a>

Firefox crash.

I've no time to look over it, but seems a overflow.

Reproducible: Always

Steps to Reproduce:
1.create a html page with a link like :

<a href="/http%3A%2F%2Fwww.proof-of-concept.fr%2Fpoc%2Fpersonnel%2FGuillaume.Hexapode%2Fnode310.html">
  test
</a>

2. visit this page.

3. clic on the link
Actual Results:  
crash

Expected Results:  
not crash ?

I use Firefox 3 Realease
No toolbarn, no pluggins.
(Reporter)

Updated

9 years ago
Version: unspecified → 3.0 Branch
You mean http://www.proof-of-concept.fr/poc/personnel/Guillaume.Hexapode/node310.html
?
I get a "La page est introuvable"
(Reporter)

Comment 2

9 years ago
<a href="http://www.proof-of-concept.fr/poc/personnel/Guillaume.Hexapode/node310.html">http://www.proof-of-concept.fr/poc/personnel/Guillaume.Hexapode/node310.html</a>
?
I get a &quot;La page est introuvable&quot;

----

You forget the slash in fornt of your URL.


Which slash?
With http://www.proof-of-concept.fr/poc/personnel/Guillaume.Hexapode/node310.html/ , I still get a "page not found" error.
(Reporter)

Comment 4

9 years ago
URL must be :

/http%3A%2F%2Fwww.proof-of-concept.fr%2Fpoc%2Fpersonnel%2FGuillaume.Hexapode%2Fnode310.html

with / in front

This web page doesn't exist. It's just to show the problem
Created attachment 325529 [details]
testcase, attached to the bug

Ah,ok, thanks. So your original code example is correct.
This is worksforme.
Pierre, does the crash also happens in safe mode?
http://support.mozilla.com/en-US/kb/Safe+Mode
Or with a new, clean profile?
(Reporter)

Comment 7

9 years ago
Work in safe mode. I'll try to look from where can come.
pierre: do you crash with the testcase Martijn attached? it's possible we're still not interpreting you correctly.
Whiteboard: [sg:needinfo]
(Reporter)

Comment 9

9 years ago
Yes I crash with the testcase Martijn attached when I'm not in safe mode.

When I use safe mode, I don't crash.
This WFM on the Mac. Martijn, did you try this on XP?
I tried on Vista.
Pierre, can you find out if one of your extensions is causing this crash?
(Reporter)

Comment 12

9 years ago
I've test extension by extension.

And look like one of my extension is causing the crash :
Download accelerator plus ( http://www.speedbit.com/ ).

Sorry I don't take time to see where crash come from before.
Pierre, thanks for finding out why you were crashing!

This looks like the same bug as bug 402735 to me.
Group: security
Status: UNCONFIRMED → RESOLVED
Last Resolved: 9 years ago
Resolution: --- → DUPLICATE
Duplicate of bug: 402735
Alias: CVE-2008-2786
You need to log in before you can comment on or make changes to this bug.