Crafted BMP image will crash Firefox in Linux (XError: 'BadAlloc (insufficient resources for operation)')

RESOLVED DUPLICATE of bug 424333

Status

()

Core
Graphics
--
critical
RESOLVED DUPLICATE of bug 424333
9 years ago
4 years ago

People

(Reporter: Carlos G., Assigned: Carlos G.)

Tracking

({testcase})

unspecified
x86
Linux
testcase
Points:
---
Bug Flags:
in-testsuite +

Firefox Tracking Flags

(Not tracked)

Details

Attachments

(3 attachments, 1 obsolete attachment)

137 bytes, image/bmp
Details
335 bytes, application/x-gzip
Details
4.48 KB, text/plain
Details
(Assignee)

Description

9 years ago
User-Agent:       Firefox 3
Build Identifier: Mozilla/5.0 (X11; U; Linux i686; es-AR; rv:1.9.0.3) Gecko/2008092416 Firefox

A BMP image with height = 65535 will make Firefox crash.

Reproducible: Always

Steps to Reproduce:
1. Try to open the crafted BMP

Actual Results:  
Firefox instantly crashes.

Expected Results:  
Display the image.
Component: General → ImageLib
Product: Firefox → Core
QA Contact: general → imagelib
Version: unspecified → 1.9.0 Branch
(Assignee)

Comment 1

9 years ago
Created attachment 346950 [details]
Test image
(Assignee)

Updated

9 years ago
Attachment #346950 - Attachment mime type: image/png → image/bmp
(Assignee)

Updated

9 years ago
Attachment #346950 - Attachment is obsolete: true
(Assignee)

Comment 2

9 years ago
Created attachment 346952 [details]
Test image
(Assignee)

Updated

9 years ago
Attachment #346952 - Attachment is obsolete: true
(Assignee)

Comment 3

9 years ago
I'm trying to upload a test image but for some reason Bugzilla converts it to a wrong type despite I select "image/bmp". I'm uploading a gzipped version now.
(Assignee)

Comment 4

9 years ago
Created attachment 346953 [details]
GZipped test image
Attachment #346952 - Attachment mime type: image/png → image/bmp
Attachment #346952 - Attachment is obsolete: false
Please provide a crash ID from this crash :
https://developer.mozilla.org/En/How_to_get_a_stacktrace_for_a_bug_report
I think I have a patch for this somewhere...
Status: UNCONFIRMED → NEW
Component: ImageLib → GFX: Thebes
Ever confirmed: true
Flags: in-testsuite?
Keywords: testcase
QA Contact: imagelib → thebes
Summary: Crafted BMP image will crash Firefox in Linux → Crafted BMP image will crash Firefox in Linux (XError: 'BadAlloc (insufficient resources for operation)')
Whiteboard: DUPEME
Version: 1.9.0 Branch → unspecified
Status: NEW → RESOLVED
Last Resolved: 9 years ago
Resolution: --- → DUPLICATE
Duplicate of bug: 424333
Crash test:
https://hg.mozilla.org/integration/mozilla-inbound/rev/82e4f1b7bbb6
Flags: in-testsuite? → in-testsuite+

Updated

4 years ago
Whiteboard: DUPEME
You need to log in before you can comment on or make changes to this bug.