Closed Bug 92201 Opened 25 years ago Closed 24 years ago

Mail crash when viewing a GIF named ".png"

Categories

(SeaMonkey :: MailNews: Message Display, defect)

x86
Linux
defect
Not set
critical

Tracking

(Not tracked)

RESOLVED WORKSFORME

People

(Reporter: felipeal, Assigned: sspitzer)

Details

(Keywords: crash)

Attachments

(4 files)

If you receive an email with a GIF image saves as .png, the mail client will crash when it tries to open that message. And the console will print: libpng error: Not a PNG file
Felipe, please attach the suspect attachment here.
Status: UNCONFIRMED → NEW
Ever confirmed: true
Keywords: crash
Summary: mail client crashes when view a wrong attachment → Mail crash when viewing a GIF named ".png"
Ok, any of the attached images should work (the second one is smaller ~ 600k) I tried to use a smaller image with xv, but that doesn't work. So, it must be something specific with the way xwd saves a gif. The version I'm using is the one that comes with X 4.0.3 for Red Hat 7.1: rpm -qf /usr/bin/X11/xwd XFree86-4.0.3-5 Finally, if I change the file name back to crasher2.gif, it doesn't crash the mail client.
I tried to reproduce this: 1. Downloaded an image, name was "dn.gif" 2. Renamed it on my desktop to "dn.png" 3. Attached the "false" PNG to an email and sent it to myself. 4. Viewed the email -- no crash, and the gif displayed properly. In other words, WORKSFORME. Stephend, Nbaca, are any of able to reproduce this? Thanks.
I tried again at home, and it still crashes. Basically, I tried in 4 browsers (and all of them crashed): - RH 7.1 with mozilla-0.9.2 and netscape6.1-PR1 - Mandrake 8.0 with mozilla-0.9.2 and netscape6.1-PR1 I will try the nightly build later (I haven't used those since 0.9.1, as from that release on mozilla got very stable, IMHO). I reported the bug before trying the nightly builds because I didn't find any mention to this pbm on the bugzilla database.
That you are able to reproduce it confirms that this is a real problem, and not just some fluke for you. However, you need to help us reproduce so we can solve the problem. Your previous attachments were screenshots of the attachments, as I understand it, but can you attach the *actual* attachment to this bug so we can try attaching/receiving it ourselves? Thanks for your time.
Felipe, free free to send an email that crashes if you are unable to attach a file that we can use to reproduce this.
Ok, I will. Also, I just tested the 2001-07-20-08 build for linux, and it crashed too (I even sent the talkback information back to netscape).
that email crashes mozilla big time. I'll get a stack trace. note, it doesn't crash 4.x
here's the stack from a slightly old win2k build: note, if you save http://bugzilla.mozilla.org/showattachment.cgi?attach_id=43535 as crash.eml, and load it in the browser, we don't crash. if you save it as crash under Local Folders (so it will be a local folder named "crash") and then load the folder, we do crash. MSVCRTD! _setjmp3 + 4 bytes nsPipe::nsPipeInputStream::ReadSegments(nsPipe::nsPipeInputStream * const 0x0581d700, unsigned int (nsIInputStream *, void *, const char *, unsigned int, unsigned int, unsigned int *)* 0x058b1a30 ReadDataOut(nsIInputStream *, void *, const char *, unsigned int, unsigned int, unsigned int *), void * 0x05821db0, unsigned int 32768, unsigned int * 0x0012f0f0) line 411 + 29 bytes nsPNGDecoder::WriteFrom(nsPNGDecoder * const 0x05821db0, nsIInputStream * 0x0581d700, unsigned int 32768, unsigned int * 0x0012f0f0) line 164 imgRequest::OnDataAvailable(imgRequest * const 0x0581c228, nsIRequest * 0x0581b0f4, nsISupports * 0x0581cf14, nsIInputStream * 0x0581d700, unsigned int 0, unsigned int 32768) line 739 + 47 bytes ProxyListener::OnDataAvailable(ProxyListener * const 0x0581cd50, nsIRequest * 0x0581b0f4, nsISupports * 0x0581cf14, nsIInputStream * 0x0581d700, unsigned int 0, unsigned int 32768) line 387 nsMimeBaseEmitter::OnFull(nsMimeBaseEmitter * const 0x0581d848, nsIOutputStream * 0x0581d714) line 272 + 47 bytes nsPipe::nsPipeOutputStream::WriteSegments(nsPipe::nsPipeOutputStream * const 0x0581d714, unsigned int (nsIOutputStream *, void *, char *, unsigned int, unsigned int, unsigned int *)* 0x10056700 nsReadFromRawBuffer(nsIOutputStream *, void *, char *, unsigned int, unsigned int, unsigned int *), void * 0x05821cf0, unsigned int 64, unsigned int * 0x0012f240) line 689 + 30 bytes nsPipe::nsPipeOutputStream::Write(nsPipe::nsPipeOutputStream * const 0x0581d714, const char * 0x05821cf0, unsigned int 64, unsigned int * 0x0012f240) line 784 nsMimeBaseEmitter::Write(nsMimeBaseEmitter * const 0x0581d840, const char * 0x03daad08, unsigned int 54, unsigned int * 0x0012f260) line 430 + 38 bytes mime_output_fn(char * 0x03daad08, int 54, void * 0x0581d4b0) line 789 MimeOptions_write(MimeDisplayOptions * 0x0581d190, char * 0x03daad08, int 54, int 1) line 1254 + 18 bytes MimeObject_write(MimeObject * 0x05821320, char * 0x03daad08, int 54, int 1) line 1274 + 24 bytes MimeInlineImage_parse_decoded_buffer(char * 0x03daad08, int 54, MimeObject * 0x05821320) line 208 + 19 bytes mime_decode_base64_buffer(MimeDecoderData * 0x058211d0, const char * 0x03daad08, int 0) line 302 + 30 bytes MimeDecoderWrite(MimeDecoderData * 0x058211d0, const char * 0x03daad08, int 72) line 598 + 17 bytes MimeLeaf_parse_buffer(char * 0x03daad08, int 72, MimeObject * 0x05821320) line 150 + 20 bytes MimeMultipart_parse_child_line(MimeObject * 0x05821a60, char * 0x03daad08, int 72, int 0) line 547 + 20 bytes MimeMultipart_parse_line(char * 0x03daad08, int 74, MimeObject * 0x05821a60) line 264 + 22 bytes convert_and_send_buffer(char * 0x03daad08, int 74, int 1, int (char *, unsigned int, void *)* 0x0437eb00 MimeMultipart_parse_line(char *, int, MimeObject *), void * 0x05821a60) line 168 + 15 bytes mime_LineBuffer(const char * 0x03d6fd90, int 74, char * * 0x05821a88, int * 0x05821a90, unsigned int * 0x05821a98, int 1, int (char *, unsigned int, void *) * 0x0437eb00 MimeMultipart_parse_line(char *, int, MimeObject *), void * 0x05821a60) line 255 + 29 bytes MimeObject_parse_buffer(char * 0x03d6fd90, int 74, MimeObject * 0x05821a60) line 255 + 49 bytes MimeMessage_parse_line(char * 0x03d6fd90, int 74, MimeObject * 0x0581d3e0) line 211 + 20 bytes convert_and_send_buffer(char * 0x03d6fd90, int 74, int 1, int (char *, unsigned int, void *)* 0x043852e0 MimeMessage_parse_line(char *, int, MimeObject *), void * 0x0581d3e0) line 168 + 15 bytes mime_LineBuffer(const char * 0x03e10399, int 2551, char * * 0x0581d408, int * 0x0581d410, unsigned int * 0x0581d418, int 1, int (char *, unsigned int, void *) * 0x043852e0 MimeMessage_parse_line(char *, int, MimeObject *), void * 0x0581d3e0) line 255 + 29 bytes MimeObject_parse_buffer(char * 0x03e0cd90, int 16384, MimeObject * 0x0581d3e0) line 255 + 49 bytes mime_display_stream_write(_nsMIMESession * 0x0581d100, const char * 0x03e0cd90, int 16384) line 837 + 20 bytes nsStreamConverter::OnDataAvailable(nsStreamConverter * const 0x0581dc00, nsIRequest * 0x0581b0f4, nsISupports * 0x0581cf10, nsIInputStream * 0x0581dcd0, unsigned int 32768, unsigned int 16384) line 887 + 24 bytes nsMailboxProtocol::ReadMessageResponse(nsIInputStream * 0x0581dcd0, unsigned int 32768, unsigned int 16384) line 543 nsMailboxProtocol::ProcessProtocolState(nsIURI * 0x0581cf14, nsIInputStream * 0x0581dcd0, unsigned int 32768, unsigned int 16384) line 632 + 20 bytes nsMsgProtocol::OnDataAvailable(nsMsgProtocol * const 0x0581b0f0, nsIRequest * 0x0581cc24, nsISupports * 0x0581cf10, nsIInputStream * 0x0581dcd0, unsigned int 32768, unsigned int 16384) line 244 + 32 bytes nsOnDataAvailableEvent::HandleEvent() line 175 + 70 bytes nsARequestObserverEvent::HandlePLEvent(PLEvent * 0x05821fb4) line 64 PL_HandleEvent(PLEvent * 0x05821fb4) line 590 + 10 bytes PL_ProcessPendingEvents(PLEventQueue * 0x0135b900) line 520 + 9 bytes _md_EventReceiverProc(HWND__ * 0x000600ee, unsigned int 49394, unsigned int 0, long 20297984) line 1071 + 9 bytes USER32! 77e13eb0() USER32! 77e1401a() USER32! 77e192da() nsAppShellService::Run(nsAppShellService * const 0x0138c7a0) line 424 main1(int 2, char * * 0x00484190, nsISupports * 0x00000000) line 1174 + 32 bytes main(int 2, char * * 0x00484190) line 1478 + 37 bytes mainCRTStartup() line 338 + 17 bytes KERNEL32! 77e87903()
It's too late now (I emailed Seth before I read Hakan's comment), but I started composing a new message and save it. When I read it from the Drafts folder it crashes too, so I'm sending a gzipped version of my Draft folder (with just that message there)
Does this help any? I don't have a mailnews tree around to test. Index: nsPNGDecoder.cpp =================================================================== RCS file: /cvsroot/mozilla/modules/libpr0n/decoders/png/nsPNGDecoder.cpp,v retrieving revision 1.20 diff -u -r1.20 nsPNGDecoder.cpp --- nsPNGDecoder.cpp 2001/07/17 01:14:06 1.20 +++ nsPNGDecoder.cpp 2001/07/25 18:21:41 @@ -141,7 +141,9 @@ // we need to do the setjmp here otherwise bad things will happen if (setjmp(decoder->mPNG->jmpbuf)) { - png_destroy_read_struct(&decoder->mPNG, &decoder->mInfo, NULL); + png_destroy_read_struct(&decoder->mPNG, + decoder->mInfo ? &decoder->mInfo : NULL, + NULL); *writeCount = 0; return NS_ERROR_FAILURE; }
I'll test out the patch.
I still crash with tor's patch. it's very strange that when loading that image as a .eml I don't crash, but when it is in a folder, I do crash.
Just a note, I installed mozilla 0.9.3 on my linux box, and it still crashes...
Severity: normal → critical
You folks do realize that none of the crasher2.png objects in the attachments is actually a PNG, don't you?
This is still a crasher on 2001121300/linux, same symptoms.
I have a non-png .png at http://mah.everybody.org/images/bad-png.png -- it crashes mozilla.
This bug seems to be fixed on 1.0 RC1. In fact, it is fixed even in the nightly build I was using: Mozilla 0.9.9+ Mozilla/5.0 (X11; U; Linux i686; en-US; rv:0.9.9+) Gecko/20020417 I tested the 2 links Mark privided and my original crashing message, and both worked fine (ie., mozilla recognized it was not a PNG file).
I visited Mark's two links with Mozilla 1.1b/Windows95 and nothing interesting happened. The ALT text is displayed where the bad PNG is called for. Glenn
worksforme with Alpha-linux 1.1 branch build 20020806 marking WFM.
Status: NEW → RESOLVED
Closed: 24 years ago
Resolution: --- → WORKSFORME
Product: Browser → Seamonkey
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Creator:
Created:
Updated:
Size: