Gnome crashes on web page load

Bug #483415 reported by AusIV
8
This bug affects 1 person
Affects Status Importance Assigned to Milestone
sun-java6 (Ubuntu)
New
Undecided
Unassigned

Bug Description

Binary package hint: sun-java6-plugin

When I have Java enabled in my browser and try to access this web page:

http://seed.ucsd.edu/~mindreader/

Gnome crashes and after a moment I find myself back at the GDM login screen.

I am running sun-java6-plugin on an updated Jaunty system. The crash happens in both Firefox 3.0 and Firefox 3.5. In case it's graphics related, I'm using an Intel 945 GMA chip.

I've restarted my system and the crash persists. I haven't been able to try the site on another computer, but I will try it on my Karmic desktop at work tomorrow.

Revision history for this message
Jamie Strandboge (jdstrand) wrote :

Thanks for taking the time to report this bug and helping to make Ubuntu better. We appreciate the difficulties you are facing, but this appears to be a "regular" (non-security) bug. I have unmarked it as a security issue since this bug does not show evidence of allowing attackers to cross privilege boundaries nor directly cause loss of data/privacy. Please feel free to report any other bugs you may find.

security vulnerability: yes → no
visibility: private → public
Revision history for this message
AusIV (linux-ausiv) wrote :

I have to disagree with the assessment that this is not a security vulnerability. This bug that allows arbitrary web pages to crash an entire Ubuntu session. This may not allow privilege escalation, but it can certainly lead to data loss if users have any unsaved documents open while browsing the web. If this vulnerability were deliberately exploited, Ubuntu desktop users could become the target of denial of service attacks.

If a web server had a bug that made it subject to denial of service attacks, I assume it would be considered a security vulnerability. Why is the same not true of a web browser?

To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.