After an evaluation, GNOME has moved from Bugzilla to GitLab. Learn more about GitLab.
No new issues can be reported in GNOME Bugzilla anymore.
To report an issue in a GNOME project, go to GNOME GitLab.
Do not go to GNOME Gitlab for: Bluefish, Doxygen, GnuCash, GStreamer, java-gnome, LDTP, NetworkManager, Tomboy.
Bug 171515 - GIF in Firefox 1.0.1 GIF-crash proff-of-concept does crash "eog" too
GIF in Firefox 1.0.1 GIF-crash proff-of-concept does crash "eog" too
Status: RESOLVED DUPLICATE of bug 300072
Product: eog
Classification: Core
Component: general
unspecified
Other other
: Normal normal
: ---
Assigned To: EOG Maintainers
EOG Maintainers
Depends on:
Blocks:
 
 
Reported: 2005-03-24 18:31 UTC by Lars Ehlers
Modified: 2005-04-25 05:13 UTC
See Also:
GNOME target: ---
GNOME version: ---



Description Lars Ehlers 2005-03-24 18:31:23 UTC
Distribution: Debian 3.1
Package: EOG
Severity: normal
Version:  2.9.0
Synopsis: GIF in Firefox 1.0.1 GIF-crash proff-of-concept does crash "eog" too
Bugzilla-Product: EOG
Bugzilla-Component: general
Bugzilla-Version: 2.9.0
BugBuddy-GnomeVersion: 2.0 (2.10.0)
Description:
Description of the crash:
Download ZIP from 
https://bugzilla.mozilla.org/show_bug.cgi?id=285595
and open test.gif with eog. eog crashes

Steps to reproduce the crash:
1. download file
2. open GIF file
3. crash

Expected Results:
eog to display message: "invlaid GIF"

How often does this happen?
every time

Additional Information:



Debugging Information:

Backtrace was generated from '/usr/bin/eog'

(no debugging symbols found)
Using host libthread_db library "/lib/tls/libthread_db.so.1".
(no debugging symbols found)
`system-supplied DSO at 0xffffe000' has disappeared; keeping its
symbols.
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
[Thread debugging using libthread_db enabled]
[New Thread -1221743904 (LWP 23107)]
[New Thread -1241535568 (LWP 23110)]
[New Thread -1233122384 (LWP 23109)]
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
(no debugging symbols found)
0xb75e5a0f in poll () from /lib/tls/libc.so.6

Thread 3 (Thread -1233122384 (LWP 23109))

  • #0 __waitpid_nocancel
    from /lib/tls/libpthread.so.0
  • #1 libgnomeui_module_info_get
    from /usr/lib/libgnomeui-2.so.0
  • #2 <signal handler called>
  • #3 raise
    from /lib/tls/libc.so.6
  • #4 abort
    from /lib/tls/libc.so.6
  • #5 ??
  • #6 ??
  • #7 ??
  • #8 ??
  • #9 ??
  • #10 ??
  • #11 ??
  • #12 ??
  • #13 ??
  • #14 ??
  • #15 ??
  • #16 ??
  • #17 ??
  • #18 ??
  • #19 ??
  • #20 ??
  • #21 ??
  • #22 ??
  • #23 ??
  • #24 ??
  • #25 ??
  • #26 ??
  • #27 ??
  • #28 ??
  • #29 ??
  • #30 ??
  • #31 ??
  • #32 ??
  • #33 ??
  • #34 ??
  • #35 ??
  • #36 ??
  • #37 ??
  • #38 ??
  • #39 ??
  • #40 ??
  • #41 ??
  • #42 g_free
    from /usr/lib/libglib-2.0.so.0
  • #0 poll
    from /lib/tls/libc.so.6




------- Bug moved to this database by unknown@bugzilla.gnome.org 2005-03-24 13:31 -------


Unknown version 2.9.0 in product EOG.  Setting version to "unspecified".
Unknown platform unknown. Setting to default platform "Other".
Unknown milestone "unknown" in product "EOG".
   Setting to default milestone for this product, '---'
The original reporter of this bug does not have
   an account here. Reassigning to the person who moved
   it here, unknown@bugzilla.gnome.org.
   Previous reporter was privat@lars-ehlers.de.
Setting to default status "UNCONFIRMED".
Setting qa contact to the default for this product.
   This bug either had no qa contact or an invalid one.

Comment 1 Elijah Newren 2005-03-25 03:58:26 UTC
I get:
  You are not authorized to access bug #285595

And unfortunately that stack trace is not very useful.  Can you provide a stack
trace with debugging symbols or upload that gif file here?
Comment 2 Lars Ehlers 2005-03-25 18:09:25 UTC
Sorry for the useless list of stack trace... it was automatically send by my new
Ubuntu gnome. Unfortunately the proof-of-concept exploit (GIF example file that
crashed Firefox 1.0.1 and is removed in Firefox 1.0.2) is not available any more
on bugzilla. Perhaps the Mozilla developers have locked it away to prevent
script kiddies for using the exploit? You might want to contact a Mozilla
developer directly to get the file?
Regards,
Lars
Comment 3 Elijah Newren 2005-04-25 05:13:54 UTC
Mozilla opened the bug back up; I can duplicate with that .gif file and I get
the same stack trace as in bug 300072, so I'll mark as a duplicate.

*** This bug has been marked as a duplicate of 300072 ***