XServer crashes when visiting web page containing PDF with Firefox

Bug #1437649 reported by Michael Mess
258
This bug affects 1 person
Affects Status Importance Assigned to Milestone
xorg (Ubuntu)
Expired
Undecided
Unassigned

Bug Description

When opening the following link with Firefox, the X Server crashes:

http://www.rauchmoebel.de/fileadmin/user_upload/Prospekte_PDF/Select/Prospekt_IMPULS_D_Webseite.pdf

As such a bug might be used for evil purposes like buffer overrun to execute arbitrary code, etc. this might be security relevant.

ProblemType: Bug
DistroRelease: Ubuntu 14.04
Package: xorg 1:7.7+1ubuntu8.1
ProcVersionSignature: Ubuntu 3.13.0-48.80-generic 3.13.11-ckt16
Uname: Linux 3.13.0-48-generic x86_64
.tmp.unity.support.test.0:

ApportVersion: 2.14.1-0ubuntu3.8
Architecture: amd64
CompizPlugins: No value set for `/apps/compiz-1/general/screen0/options/active_plugins'
CompositorRunning: None
CurrentDesktop: XFCE
Date: Sat Mar 28 16:35:21 2015
DistUpgraded: Fresh install
DistroCodename: trusty
DistroVariant: ubuntu
ExtraDebuggingInterest: Yes
GraphicsCard:
 Advanced Micro Devices, Inc. [AMD/ATI] Kabini [Radeon HD 8280] [1002:9836] (prog-if 00 [VGA controller])
   Subsystem: ASRock Incorporation Device [1849:9836]
InstallationDate: Installed on 2014-02-25 (395 days ago)
InstallationMedia: Ubuntu 14.04.1 LTS "Trusty Tahr" - Release amd64 (20140722.2)
MachineType: To Be Filled By O.E.M. To Be Filled By O.E.M.
ProcKernelCmdLine: BOOT_IMAGE=/boot/vmlinuz-3.13.0-48-generic root=UUID=5e706392-b33a-488d-bd51-fc1d86c7ed43 ro quiet splash vt.handoff=7
SourcePackage: xorg
UpgradeStatus: No upgrade log present (probably fresh install)
dmi.bios.date: 02/21/2014
dmi.bios.vendor: American Megatrends Inc.
dmi.bios.version: P1.10
dmi.board.name: AM1B-ITX
dmi.board.vendor: ASRock
dmi.chassis.asset.tag: To Be Filled By O.E.M.
dmi.chassis.type: 3
dmi.chassis.vendor: To Be Filled By O.E.M.
dmi.chassis.version: To Be Filled By O.E.M.
dmi.modalias: dmi:bvnAmericanMegatrendsInc.:bvrP1.10:bd02/21/2014:svnToBeFilledByO.E.M.:pnToBeFilledByO.E.M.:pvrToBeFilledByO.E.M.:rvnASRock:rnAM1B-ITX:rvr:cvnToBeFilledByO.E.M.:ct3:cvrToBeFilledByO.E.M.:
dmi.product.name: To Be Filled By O.E.M.
dmi.product.version: To Be Filled By O.E.M.
dmi.sys.vendor: To Be Filled By O.E.M.
version.compiz: compiz 1:0.9.11.3+14.04.20150122-0ubuntu1
version.ia32-libs: ia32-libs N/A
version.libdrm2: libdrm2 2.4.56-1~ubuntu2
version.libgl1-mesa-dri: libgl1-mesa-dri 10.1.3-0ubuntu0.4
version.libgl1-mesa-dri-experimental: libgl1-mesa-dri-experimental N/A
version.libgl1-mesa-glx: libgl1-mesa-glx 10.1.3-0ubuntu0.4
version.xserver-xorg-core: xserver-xorg-core 2:1.15.1-0ubuntu2.7
version.xserver-xorg-input-evdev: xserver-xorg-input-evdev 1:2.8.2-1ubuntu2
version.xserver-xorg-video-ati: xserver-xorg-video-ati 1:7.3.0-1ubuntu3.1
version.xserver-xorg-video-intel: xserver-xorg-video-intel 2:2.99.910-0ubuntu1.4
version.xserver-xorg-video-nouveau: xserver-xorg-video-nouveau 1:1.0.10-1ubuntu2
xserver.bootTime: Sat Mar 28 16:31:08 2015
xserver.configfile: default
xserver.devices:
 input Power Button KEYBOARD, id 6
 input Power Button KEYBOARD, id 7
 input Lite-On Technology Corp. ThinkPad USB Keyboard with TrackPoint KEYBOARD, id 8
 input Lite-On Technology Corp. ThinkPad USB Keyboard with TrackPoint KEYBOARD, id 9
xserver.errors:

xserver.logfile: /var/log/Xorg.0.log
xserver.outputs: Output HDMI-0 HDMI-1 VGA-0
xserver.version: 2:1.15.1-0ubuntu2.7
xserver.video_driver: radeon
---
.tmp.unity.support.test.0:

ApportVersion: 2.14.1-0ubuntu3.10
Architecture: amd64
CompizPlugins: No value set for `/apps/compiz-1/general/screen0/options/active_plugins'
CompositorRunning: None
CurrentDesktop: XFCE
DistUpgraded: Fresh install
DistroCodename: trusty
DistroRelease: Ubuntu 14.04
DistroVariant: ubuntu
ExtraDebuggingInterest: Yes
GraphicsCard:
 Advanced Micro Devices, Inc. [AMD/ATI] Kabini [Radeon HD 8280] [1002:9836] (prog-if 00 [VGA controller])
   Subsystem: ASRock Incorporation Device [1849:9836]
InstallationDate: Installed on 2014-02-25 (446 days ago)
InstallationMedia: Ubuntu 14.04.1 LTS "Trusty Tahr" - Release amd64 (20140722.2)
MachineType: To Be Filled By O.E.M. To Be Filled By O.E.M.
Package: xorg 1:7.7+1ubuntu8.1
PackageArchitecture: amd64
ProcKernelCmdLine: BOOT_IMAGE=/boot/vmlinuz-3.13.0-52-generic root=UUID=5e706392-b33a-488d-bd51-fc1d86c7ed43 ro quiet splash vt.handoff=7
ProcVersionSignature: Ubuntu 3.13.0-52.86-generic 3.13.11-ckt18
Tags: trusty ubuntu
Uname: Linux 3.13.0-52-generic x86_64
UpgradeStatus: No upgrade log present (probably fresh install)
UserGroups: adm cdrom dip lpadmin plugdev sambashare sudo
_MarkForUpload: True
dmi.bios.date: 02/21/2014
dmi.bios.vendor: American Megatrends Inc.
dmi.bios.version: P1.10
dmi.board.name: AM1B-ITX
dmi.board.vendor: ASRock
dmi.chassis.asset.tag: To Be Filled By O.E.M.
dmi.chassis.type: 3
dmi.chassis.vendor: To Be Filled By O.E.M.
dmi.chassis.version: To Be Filled By O.E.M.
dmi.modalias: dmi:bvnAmericanMegatrendsInc.:bvrP1.10:bd02/21/2014:svnToBeFilledByO.E.M.:pnToBeFilledByO.E.M.:pvrToBeFilledByO.E.M.:rvnASRock:rnAM1B-ITX:rvr:cvnToBeFilledByO.E.M.:ct3:cvrToBeFilledByO.E.M.:
dmi.product.name: To Be Filled By O.E.M.
dmi.product.version: To Be Filled By O.E.M.
dmi.sys.vendor: To Be Filled By O.E.M.
version.compiz: compiz 1:0.9.11.3+14.04.20150313-0ubuntu1
version.ia32-libs: ia32-libs N/A
version.libdrm2: libdrm2 2.4.60-2~ubuntu14.04.1
version.libgl1-mesa-dri: libgl1-mesa-dri 10.1.3-0ubuntu0.4
version.libgl1-mesa-dri-experimental: libgl1-mesa-dri-experimental N/A
version.libgl1-mesa-glx: libgl1-mesa-glx 10.1.3-0ubuntu0.4
version.xserver-xorg-core: xserver-xorg-core 2:1.15.1-0ubuntu2.7
version.xserver-xorg-input-evdev: xserver-xorg-input-evdev 1:2.8.2-1ubuntu2
version.xserver-xorg-video-ati: xserver-xorg-video-ati 1:7.3.0-1ubuntu3.1
version.xserver-xorg-video-intel: xserver-xorg-video-intel 2:2.99.910-0ubuntu1.6
version.xserver-xorg-video-nouveau: xserver-xorg-video-nouveau 1:1.0.10-1ubuntu2
xserver.bootTime: Mon May 18 19:59:38 2015
xserver.configfile: default
xserver.devices:
 input Power Button KEYBOARD, id 6
 input Power Button KEYBOARD, id 7
 input Lite-On Technology Corp. ThinkPad USB Keyboard with TrackPoint KEYBOARD, id 8
 input Lite-On Technology Corp. ThinkPad USB Keyboard with TrackPoint KEYBOARD, id 9
xserver.errors:

xserver.logfile: /var/log/Xorg.0.log
xserver.outputs: Output HDMI-0 HDMI-1 VGA-0
xserver.version: 2:1.15.1-0ubuntu2.7
xserver.video_driver: radeon

Revision history for this message
Michael Mess (michael-michaelmess) wrote :
information type: Private Security → Public Security
Revision history for this message
Marc Deslauriers (mdeslaur) wrote :

I can't reproduce this, either in a VM, or on real hardware that uses the nouveau driver.

Are you still able to reproduce this with all current updates applied?

Changed in xorg (Ubuntu):
status: New → Incomplete
Revision history for this message
Michael Mess (michael-michaelmess) wrote :

Yes, I just was able to reproduce.

I will try to add some more information...

Revision history for this message
Michael Mess (michael-michaelmess) wrote : BootDmesg.txt

apport information

tags: added: apport-collected
description: updated
Revision history for this message
Michael Mess (michael-michaelmess) wrote : BootLog.txt

apport information

Revision history for this message
Michael Mess (michael-michaelmess) wrote : CurrentDmesg.txt

apport information

Revision history for this message
Michael Mess (michael-michaelmess) wrote : Dependencies.txt

apport information

Revision history for this message
Michael Mess (michael-michaelmess) wrote : DpkgLog.txt

apport information

Revision history for this message
Michael Mess (michael-michaelmess) wrote : GconfCompiz.txt

apport information

Revision history for this message
Michael Mess (michael-michaelmess) wrote : LightdmDisplayLog.txt

apport information

Revision history for this message
Michael Mess (michael-michaelmess) wrote : LightdmGreeterLog.txt

apport information

Revision history for this message
Michael Mess (michael-michaelmess) wrote : LightdmGreeterLogOld.txt

apport information

Revision history for this message
Michael Mess (michael-michaelmess) wrote : LightdmLog.txt

apport information

Revision history for this message
Michael Mess (michael-michaelmess) wrote : Lspci.txt

apport information

Revision history for this message
Michael Mess (michael-michaelmess) wrote : Lsusb.txt

apport information

Revision history for this message
Michael Mess (michael-michaelmess) wrote : MonitorsUser.xml.txt

apport information

Revision history for this message
Michael Mess (michael-michaelmess) wrote : ProcCpuinfo.txt

apport information

Revision history for this message
Michael Mess (michael-michaelmess) wrote : ProcEnviron.txt

apport information

Revision history for this message
Michael Mess (michael-michaelmess) wrote : ProcInterrupts.txt

apport information

Revision history for this message
Michael Mess (michael-michaelmess) wrote : ProcModules.txt

apport information

Revision history for this message
Michael Mess (michael-michaelmess) wrote : UdevDb.txt

apport information

Revision history for this message
Michael Mess (michael-michaelmess) wrote : UdevLog.txt

apport information

Revision history for this message
Michael Mess (michael-michaelmess) wrote : UnitySupportTest.txt

apport information

Revision history for this message
Michael Mess (michael-michaelmess) wrote : XorgLog.txt

apport information

Revision history for this message
Michael Mess (michael-michaelmess) wrote : XorgLogOld.txt

apport information

Revision history for this message
Michael Mess (michael-michaelmess) wrote : Xrandr.txt

apport information

Revision history for this message
Michael Mess (michael-michaelmess) wrote : xdpyinfo.txt

apport information

Revision history for this message
Michael Mess (michael-michaelmess) wrote :

Created crash report with apport-bug: #1456303

Revision history for this message
Michael Mess (michael-michaelmess) wrote :

Created crash report with apport-bug: bug 1456303

Revision history for this message
Michael Mess (michael-michaelmess) wrote :

Marked this bug as a duplicate of bug #1456303 (I have created that bug after reproducing the crash).

Revision history for this message
Michael Mess (michael-michaelmess) wrote :

Removed duplicate status, because the bug #1456303 lacks valuable debug symbols.
I have to reproduce again later.

Revision history for this message
Michael Mess (michael-michaelmess) wrote :

Reproduced issue and created new crash report: Bug #1456314 : Xorg crashed with SIGABRT in fast_composite_tiled_repeat()

Revision history for this message
Launchpad Janitor (janitor) wrote :

[Expired for xorg (Ubuntu) because there has been no activity for 60 days.]

Changed in xorg (Ubuntu):
status: Incomplete → Expired
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.