Closed Bug 463696 Opened 12 years ago Closed 12 years ago

Crafted BMP image will crash Firefox in Linux (XError: 'BadAlloc (insufficient resources for operation)')

Categories

(Core :: Graphics, defect, critical)

x86
Linux
defect
Not set
critical

Tracking

()

RESOLVED DUPLICATE of bug 424333

People

(Reporter: charlie.brown.uy, Assigned: charlie.brown.uy)

Details

(Keywords: testcase)

Attachments

(3 files, 1 obsolete file)

User-Agent:       Firefox 3
Build Identifier: Mozilla/5.0 (X11; U; Linux i686; es-AR; rv:1.9.0.3) Gecko/2008092416 Firefox

A BMP image with height = 65535 will make Firefox crash.

Reproducible: Always

Steps to Reproduce:
1. Try to open the crafted BMP

Actual Results:  
Firefox instantly crashes.

Expected Results:  
Display the image.
Component: General → ImageLib
Product: Firefox → Core
QA Contact: general → imagelib
Version: unspecified → 1.9.0 Branch
Attached image Test image (obsolete) —
Attachment #346950 - Attachment mime type: image/png → image/bmp
Attachment #346950 - Attachment is obsolete: true
Attached image Test image
Attachment #346952 - Attachment is obsolete: true
I'm trying to upload a test image but for some reason Bugzilla converts it to a wrong type despite I select "image/bmp". I'm uploading a gzipped version now.
Attached file GZipped test image
Attachment #346952 - Attachment mime type: image/png → image/bmp
Attachment #346952 - Attachment is obsolete: false
Attached file stack
I think I have a patch for this somewhere...
Status: UNCONFIRMED → NEW
Component: ImageLib → GFX: Thebes
Ever confirmed: true
Flags: in-testsuite?
Keywords: testcase
QA Contact: imagelib → thebes
Summary: Crafted BMP image will crash Firefox in Linux → Crafted BMP image will crash Firefox in Linux (XError: 'BadAlloc (insufficient resources for operation)')
Whiteboard: DUPEME
Version: 1.9.0 Branch → unspecified
Status: NEW → RESOLVED
Closed: 12 years ago
Resolution: --- → DUPLICATE
Duplicate of bug: 424333
Crash test:
https://hg.mozilla.org/integration/mozilla-inbound/rev/82e4f1b7bbb6
Flags: in-testsuite? → in-testsuite+
Whiteboard: DUPEME
You need to log in before you can comment on or make changes to this bug.