Comment 2 for bug 483415

Revision history for this message
AusIV (linux-ausiv) wrote :

I have to disagree with the assessment that this is not a security vulnerability. This bug that allows arbitrary web pages to crash an entire Ubuntu session. This may not allow privilege escalation, but it can certainly lead to data loss if users have any unsaved documents open while browsing the web. If this vulnerability were deliberately exploited, Ubuntu desktop users could become the target of denial of service attacks.

If a web server had a bug that made it subject to denial of service attacks, I assume it would be considered a security vulnerability. Why is the same not true of a web browser?