Bug#545555: Segfault on opening spam email

Adam Majer adamm at zombino.com
Tue Sep 8 06:32:46 BST 2009


Package: icedove
Version: 2.0.0.22-1
Severity: important

Considering the crash occurs on opening remotely sent mail, this may
be of some security concern.

(gdb) bt
#0  0x00007f8e8421e5db in raise (sig=<value optimized out>)
    at ../nptl/sysdeps/unix/sysv/linux/pt-raise.c:41
#1  0x00000000004105e1 in nsProfileLock::FatalSignalHandler (signo=11)
    at nsProfileLock.cpp:206
#2  <signal handler called>
#3  0x0000000000000000 in ?? ()
#4  0x00007f8e727558b2 in
nsCSSFrameConstructor::GetAbsoluteContainingBlock (
    this=0x231ac50, aFrame=0x27c85c0) at
    nsCSSFrameConstructor.cpp:8092
#5  0x00007f8e72767211 in
nsCSSFrameConstructor::CantRenderReplacedElement (
    this=0x231ac50, aFrame=0x27c40a0) at
    nsCSSFrameConstructor.cpp:11123
#6  0x00007f8e72791056 in CantRenderReplacedElementEvent::HandleEvent
(
    this=<value optimized out>) at nsPresShell.cpp:4209
#7  0x00007f8e72791079 in HandleCantRenderReplacedElementEvent (
    aEvent=0x27c85c0) at nsPresShell.cpp:4076
#8  0x00007f8e84af0b39 in PL_HandleEvent (self=0x27cabf0) at
plevent.c:688
#9  0x00007f8e84af0ded in PL_ProcessPendingEvents (self=0x112be10)
    at plevent.c:623
#10 0x00007f8e84af26bb in nsEventQueueImpl::ProcessPendingEvents (
    this=0x10f47b0) at nsEventQueue.cpp:448
#11 0x00007f8e75d6f452 in event_processor_callback (
    source=<value optimized out>, condition=G_IO_IN, data=0xca2d94e8)
    at nsAppShell.cpp:67
#12 0x00007f8e81c307aa in g_main_context_dispatch ()
   from /usr/lib/libglib-2.0.so.0


The spam message causing the crash is attached. Extracted with mutt.

- Adam



-- System Information:
Debian Release: squeeze/sid
  APT prefers unstable
  APT policy: (500, 'unstable'), (50, 'experimental')
Architecture: amd64 (x86_64)

Kernel: Linux 2.6.30-1-amd64 (SMP w/2 CPU cores)
Locale: LANG=en_CA.UTF-8, LC_CTYPE=en_CA.UTF-8 (charmap=UTF-8)
Shell: /bin/sh linked to /bin/bash

Versions of packages icedove depends on:
ii  debianutils            3.2.1             Miscellaneous utilities specific t
ii  fontconfig             2.6.0-4           generic font configuration library
ii  libatk1.0-0            1.26.0-1          The ATK accessibility toolkit
ii  libc6                  2.9-25            GNU C Library: Shared libraries
ii  libcairo2              1.8.8-2           The Cairo 2D vector graphics libra
ii  libfontconfig1         2.6.0-4           generic font configuration library
ii  libfreetype6           2.3.9-5           FreeType 2 font engine, shared lib
ii  libgcc1                1:4.4.1-3         GCC support library
ii  libglib2.0-0           2.20.4-1          The GLib library of C routines
ii  libgtk2.0-0            2.16.5-1          The GTK+ graphical user interface 
ii  libhunspell-1.2-0      1.2.8-4           spell checker and morphological an
ii  libjpeg62              6b-15             The Independent JPEG Group's JPEG 
ii  libnspr4-0d            4.8-1             NetScape Portable Runtime Library
ii  libnss3-1d             3.12.3.1-1        Network Security Service libraries
ii  libpango1.0-0          1.24.5-1          Layout and rendering of internatio
ii  libpng12-0             1.2.39-1          PNG library - runtime
ii  libstdc++6             4.4.1-3           The GNU Standard C++ Library v3
ii  libx11-6               2:1.2.2-1         X11 client-side library
ii  libxft2                2.1.13-3          FreeType-based font drawing librar
ii  libxinerama1           2:1.0.3-2         X11 Xinerama extension library
ii  libxrender1            1:0.9.4-2         X Rendering Extension client libra
ii  libxt6                 1:1.0.6-1         X11 toolkit intrinsics library
ii  psmisc                 22.8-1            utilities that use the proc file s
ii  zlib1g                 1:1.2.3.3.dfsg-15 compression library - runtime

icedove recommends no packages.

Versions of packages icedove suggests:
ii  icedove-gnome-support         2.0.0.22-1 Support for Gnome in Icedove
ii  latex-xft-fonts               1.6.4-1    TrueType versions of some TeX font
ii  libthai0                      0.1.12-1   Thai language support library

-- no debconf information
-------------- next part --------------
A non-text attachment was scrubbed...
Name: spam.bz2
Type: application/x-bzip2
Size: 16188 bytes
Desc: not available
Url : https://lists.ubuntu.com/archives/ubuntu-mozillateam/attachments/20090908/81104a8f/attachment-0001.bin 


More information about the Ubuntu-mozillateam mailing list