Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 114940 - www-client/mozilla-firefox{-bin} History crash in firefox-1.0.x and firefox-1.5
Summary: www-client/mozilla-firefox{-bin} History crash in firefox-1.0.x and firefox-1.5
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Linux
Classification: Unclassified
Component: Current packages (show other bugs)
Hardware: All Linux
: High major (vote)
Assignee: Mozilla Gentoo Team
URL: https://bugzilla.mozilla.org/show_bug...
Whiteboard: [ebuild]
Keywords:
Depends on:
Blocks:
 
Reported: 2005-12-08 18:23 UTC by Jory A. Pratt
Modified: 2006-01-13 10:33 UTC (History)
0 users

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Jory A. Pratt 2005-12-08 18:23:32 UTC
I have patches the vulnerability in both 1.0.7 and 1.5 need to mark 1.0.7-r4
stable. More info on the vulnerability can be found at
http://packetstormsecurity.org/0512-exploits/firefox-1.5-buffer-overflow.txt
Comment 1 Jory A. Pratt 2005-12-08 22:40:16 UTC
Hold off on marking stable as I need to add the mork patch, sorry it will be
added first thing tomorrow morning as I am testing it right now to make sure we
do not break compilation or cause any other problems.
Comment 2 Tavis Ormandy (RETIRED) gentoo-dev 2005-12-09 01:59:00 UTC
based on the official response here http://www.mozilla.org/security/history-
title.html and the fact that it is clearly being misrepresented as a buffer 
overflow, when it is just abusing the fact that an O(n^2) algorithm is being 
used to process the history file, this is a client DoS which is not normally 
handled by the security team.

Reassigning to mozilla team.
Comment 3 Jory A. Pratt 2005-12-09 07:31:13 UTC
Aight 1.0.7-r4 is ready to be marked stable by respective archs. I have also
pushed -r2 on 1.5 so all ~arch users get the update. This was nothing more then
adding the mork patch for completeness.
Comment 4 Joshua Jackson (RETIRED) gentoo-dev 2005-12-09 20:41:07 UTC
Just did a test of the vulnerability with the new -r4. It does allow you to
restart firefox after the code. However when the vulnerability test code runs,
firefox loses all borders, visually fickers..and kills metacity. However, with
fluxbox, this crashing of the windowmanager doesn't happen.

built as such:

 www-client/mozilla-firefox-1.0.7-r4  -debug -gnome +ipv6 -java -mozcalendar
-mozdevelop -moznoxft -mozsvg +truetype -xinerama -xprint

Will be testing with +gnome, to see if its something slightly funky there.
Comment 5 Joshua Jackson (RETIRED) gentoo-dev 2005-12-12 21:11:04 UTC
stable on x86
Comment 6 Gustavo Zacarias (RETIRED) gentoo-dev 2005-12-14 04:50:46 UTC
sparc stable.
Comment 7 Jose Luis Rivero (yoswink) (RETIRED) gentoo-dev 2005-12-14 17:09:45 UTC
Stable on alpha
Comment 8 Jory A. Pratt 2005-12-14 17:26:34 UTC
Stable on amd64.
Comment 9 Luca Barbato gentoo-dev 2006-01-06 21:38:41 UTC
hansmi marked it
Comment 10 Tim Yamin (RETIRED) gentoo-dev 2006-01-13 09:59:04 UTC
IA64 done; no other archs left, closing bug.
Comment 11 Jory A. Pratt 2006-01-13 10:33:59 UTC
closing as (In reply to comment #10)
> IA64 done; no other archs left, closing bug.
> 

closing as Tim did not