Closed Bug 550595 Opened 14 years ago Closed 14 years ago

Firefox 3.6 hangs ( possible DoS ) with a lot of *> chars

Categories

(Firefox :: General, defect)

3.6 Branch
x86
Windows 7
defect
Not set
major

Tracking

()

RESOLVED DUPLICATE of bug 548495

People

(Reporter: Lostmon, Unassigned)

Details

(Keywords: hang, Whiteboard: [sg:dos]DUPEME)

Attachments

(1 file)

User-Agent:       Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; Trident/4.0; GTB6.4; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; MS-RTC LM 8; Tablet PC 2.0) chromeframe/5.0.342.0
Build Identifier: Mozilla/5.0 (Windows; U; Windows NT 6.1; es-ES; rv:1.9.2) Gecko/20100115 Firefox/3.6

Firefox is hang wen open a pseudo malformed web page that contains a lot of *> chars

Reproducible: Always

Steps to Reproduce:
1.open the malformed doc wait a seconds
2.try to select ome text or something
3.try to code the tab or stop 
Actual Results:  
browser hangs all time and it can cause a DoS

Expected Results:  
browser hangs all time and it can cause a DoS
Attached file test case or PoC
i have found in the wild wen i test some bug in webkit soft see also http://www.securityfocus.com/bid/38398 exploit and open it directly 

open attached file via file:/// protocol handler or via http:// in al cases firefox hang.
Group: core-security
I do believe this hang was already fixed on trunk...
Severity: critical → major
Keywords: hang
Whiteboard: DUPEME
Version: unspecified → 3.6 Branch
Whiteboard: DUPEME → [sg:dos]DUPEME
(In reply to comment #2)
> I do believe this hang was already fixed on trunk...

You probably are referring to bug 548495.
Test it in linux Debian testing in Iceweasel browser

browser signature =>
 Mozilla/5.0 (X11; U; Linux i686; es-ES; rv:1.9.1.6) Gecko/20091216 Iceweasel/3.5.8 (like Firefox/3.5.8)

And it hangs too
exactly.
reporter, this will be fixed in 3.6.2 and 3.5.9
Status: UNCONFIRMED → RESOLVED
Closed: 14 years ago
Resolution: --- → DUPLICATE
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Creator:
Created:
Updated:
Size: