Re: Netscape 6/7 crashes by a simple stylesheet...

From: Raj Mathur (raju@linux-delhi.org)
Date: 02/26/03

  • Next message: Karol Wiesek: "GOnicus System Administrator php injection"
    Date: Wed, 26 Feb 2003 09:13:04 +0530
    To: bugtraq@securityfocus.com
    From: Raj Mathur <raju@linux-delhi.org>
    
    

    >>>>> "Jocke" == jux <jux@beer.com> writes:

        Jocke> Hi, I'm new here so I don't know if I posted this in the
        Jocke> correct list...

        Jocke> I've found out that some simple CSS-code can crash Netscape
        Jocke> 6 and 7.

        Jocke> This is a simple html-page containing this code:

        Jocke> <html> <body> <div style="position:absolute;">

        Jocke> <div style="position:absolute; overflow:scroll">
     
        Jocke> </div> </div> </body> </html>

        Jocke> Was this already known?

    Tested on following browsers on Red Hat Linux 8.0, i386:

    galeon-1.2.6-0.8.0: Consumes 100% CPU but continues to respond to
    events.

    kdebase-3.0.3-14 (Konqueror): No effect

    mozilla-1.0.1-26: Consumes 100% CPU, stops responding to events (or
    takes overly long to respond -- I didn't wait more than a couple of
    minutes).

    netscape-communicator-4.79-1: No effect.

    Regards,

    -- Raju

        Jocke> /Jocke

    -- 
    Raj Mathur                raju@kandalaya.org      http://kandalaya.org/
                          It is the mind that moves
    


    Relevant Pages

    • [Full-Disclosure] Re: Netscape 6/7 crashes by a simple stylesheet...
      ... Jocke> correct list... ... Tested on following browsers on Red Hat Linux 8.0, ... Consumes 100% CPU, ...
      (Full-Disclosure)
    • Re: AfxBeginThread startup times and overhead
      ... cosuming CPU time that could have been used to run the thread instead. ... it always consumes as much of the CPU as it can get. ... no sequencing dependency once it has started. ... MVP Tips: http://www.flounder.com/mvp_tips.htm ...
      (microsoft.public.vc.mfc)
    • Re: [RFT][patch] Scheduling for HTT and not only
      ... About 0.05% CPU time use for process that supposed to be CPU-bound. ... my patch has nothing to do with the problem. ... but not in this case when dnets consumes all available CPUs. ... As result, while dnets threads ...
      (freebsd-hackers)
    • Re: efficiency of JList setElementAt()
      ... >> consumes 31% of the system CPU when these operations occur but if I ... > PL&F revalidates and repaints the entire list if any of it changes. ...
      (comp.lang.java.gui)
    • Re: [RFT][patch] Scheduling for HTT and not only
      ... On 03/03/12 11:12, Alexander Motin wrote: ... About 0.05% CPU time use for process that supposed to be CPU-bound. ... but not in this case when dnets consumes all available CPUs. ...
      (freebsd-hackers)