Firefox DoS/memory corruption flaw in javascript. Bugtraq ID 19488

Bug #69003 reported by Andrew Clunis
256
Affects Status Importance Assigned to Milestone
firefox (Baltix)
Invalid
Undecided
Unassigned
firefox (Ubuntu)
Fix Released
Medium
Mozilla Bugs

Bug Description

http://www.securityfocus.com/bid/19488/info

I went to the exploit code page at:

http://lcamtuf.coredump.cx/ffoxdie.html (will crash FF!)

and it successfully caused Firefox 2.0 to fail with signal 11. This was on a fully up to date Ubuntu 6.10 x86_64 machine.

CVE References

Revision history for this message
Andrew Clunis (orospakr) wrote :

Apport crashdump.

Revision history for this message
Andrew Clunis (orospakr) wrote :

A friend of mine on Windows XP (32-bit) confirmed that this works against upstream's current production release as well.

Revision history for this message
SKemper (wkemper) wrote :

This happens without fail for me at http://www.nvidia.com

Revision history for this message
SKemper (wkemper) wrote :

And again, another crash log in case the first one wasn't enough.

David Farning (dfarning)
Changed in firefox:
assignee: nobody → mozillateam
importance: Undecided → Medium
Kees Cook (kees)
Changed in firefox:
status: Unconfirmed → Confirmed
David Farning (dfarning)
Changed in firefox:
assignee: mozillateam → mozilla-bugs
Revision history for this message
RParr (rparr) wrote :

I recently installed Feisty Herd 5. When Konqueror crashed and asked if it should report the error it came back that the error was already reported. I am assuming it correctly diagnosed the error.

The error occurs in Konquer, Firefox, and Seamonkey when trying to access many different sites. In particular accuweather.com (actually http://wwwa.accuweather.com/forecast-15day.asp?partner=accuweather&traveler=0&zipChg=1&zipcode=97213&metric=0)
will cause all three browsers to crash.

This error does not occur when this same site is accessed from Debian etch or and old Red Hat 8 when using the same three browsers.

The only plugins I have installed are the nonfree-flash, Java, and VLC. The crash occurs even if only the flash plugin is installed.

Revision history for this message
Kees Cook (kees) wrote :

Hi RParr, I cannot reproduce this, so I assume it is your nonfree-flash plugin. If that's true, this bug (69003) is not what you're seeing. This bug is specific to a javascript crash that was recently fixed in Firefox 2.0.0.2.

Kees Cook (kees)
Changed in firefox:
status: Confirmed → Fix Released
Revision history for this message
Jamie Strandboge (jdstrand) wrote :

Is this still an issue for Baltix?

Changed in firefox:
status: New → Incomplete
Revision history for this message
Jamie Strandboge (jdstrand) wrote :

We are closing this bug report because it lacks the information we need to investigate the problem, as described in the previous comments. Please reopen it if you can give us the missing information, and don't hesitate to submit bug reports in the future. To reopen the bug report you can click on the current status, under the Status column, and change the Status back to "New". Thanks again!

Changed in firefox:
status: Incomplete → Invalid
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.