GNOME Bugzilla – Bug 171515
GIF in Firefox 1.0.1 GIF-crash proff-of-concept does crash "eog" too
Last modified: 2005-04-25 05:13:54 UTC
Distribution: Debian 3.1 Package: EOG Severity: normal Version: 2.9.0 Synopsis: GIF in Firefox 1.0.1 GIF-crash proff-of-concept does crash "eog" too Bugzilla-Product: EOG Bugzilla-Component: general Bugzilla-Version: 2.9.0 BugBuddy-GnomeVersion: 2.0 (2.10.0) Description: Description of the crash: Download ZIP from https://bugzilla.mozilla.org/show_bug.cgi?id=285595 and open test.gif with eog. eog crashes Steps to reproduce the crash: 1. download file 2. open GIF file 3. crash Expected Results: eog to display message: "invlaid GIF" How often does this happen? every time Additional Information: Debugging Information: Backtrace was generated from '/usr/bin/eog' (no debugging symbols found) Using host libthread_db library "/lib/tls/libthread_db.so.1". (no debugging symbols found) `system-supplied DSO at 0xffffe000' has disappeared; keeping its symbols. (no debugging symbols found) (no debugging symbols found) (no debugging symbols found) (no debugging symbols found) (no debugging symbols found) (no debugging symbols found) (no debugging symbols found) (no debugging symbols found) (no debugging symbols found) (no debugging symbols found) (no debugging symbols found) (no debugging symbols found) (no debugging symbols found) (no debugging symbols found) (no debugging symbols found) (no debugging symbols found) (no debugging symbols found) (no debugging symbols found) (no debugging symbols found) [Thread debugging using libthread_db enabled] [New Thread -1221743904 (LWP 23107)] [New Thread -1241535568 (LWP 23110)] [New Thread -1233122384 (LWP 23109)] (no debugging symbols found) (no debugging symbols found) (no debugging symbols found) (no debugging symbols found) (no debugging symbols found) (no debugging symbols found) (no debugging symbols found) (no debugging symbols found) (no debugging symbols found) (no debugging symbols found) (no debugging symbols found) (no debugging symbols found) (no debugging symbols found) (no debugging symbols found) (no debugging symbols found) (no debugging symbols found) (no debugging symbols found) (no debugging symbols found) (no debugging symbols found) (no debugging symbols found) (no debugging symbols found) (no debugging symbols found) (no debugging symbols found) (no debugging symbols found) (no debugging symbols found) (no debugging symbols found) (no debugging symbols found) (no debugging symbols found) (no debugging symbols found) (no debugging symbols found) (no debugging symbols found) (no debugging symbols found) (no debugging symbols found) (no debugging symbols found) (no debugging symbols found) (no debugging symbols found) (no debugging symbols found) (no debugging symbols found) (no debugging symbols found) (no debugging symbols found) (no debugging symbols found) (no debugging symbols found) (no debugging symbols found) (no debugging symbols found) (no debugging symbols found) (no debugging symbols found) (no debugging symbols found) (no debugging symbols found) (no debugging symbols found) (no debugging symbols found) (no debugging symbols found) 0xb75e5a0f in poll () from /lib/tls/libc.so.6
+ Trace 57286
Thread 3 (Thread -1233122384 (LWP 23109))
------- Bug moved to this database by unknown@bugzilla.gnome.org 2005-03-24 13:31 ------- Unknown version 2.9.0 in product EOG. Setting version to "unspecified". Unknown platform unknown. Setting to default platform "Other". Unknown milestone "unknown" in product "EOG". Setting to default milestone for this product, '---' The original reporter of this bug does not have an account here. Reassigning to the person who moved it here, unknown@bugzilla.gnome.org. Previous reporter was privat@lars-ehlers.de. Setting to default status "UNCONFIRMED". Setting qa contact to the default for this product. This bug either had no qa contact or an invalid one.
I get: You are not authorized to access bug #285595 And unfortunately that stack trace is not very useful. Can you provide a stack trace with debugging symbols or upload that gif file here?
Sorry for the useless list of stack trace... it was automatically send by my new Ubuntu gnome. Unfortunately the proof-of-concept exploit (GIF example file that crashed Firefox 1.0.1 and is removed in Firefox 1.0.2) is not available any more on bugzilla. Perhaps the Mozilla developers have locked it away to prevent script kiddies for using the exploit? You might want to contact a Mozilla developer directly to get the file? Regards, Lars
Mozilla opened the bug back up; I can duplicate with that .gif file and I get the same stack trace as in bug 300072, so I'll mark as a duplicate. *** This bug has been marked as a duplicate of 300072 ***