[Author Prev][Author Next][Thread Prev][Thread Next][Author Index][Thread Index]
Re: [tor-bugs] #9901 [Tor bundles/installation]: DoS of TBB 2.4/3.0 when no Content-Type header and more than 512 bytes of content are sent
#9901: DoS of TBB 2.4/3.0 when no Content-Type header and more than 512 bytes of
content are sent
------------------------------------------+--------------------------------
Reporter: sqrt2 | Owner: erinn
Type: defect | Status: new
Priority: normal | Milestone:
Component: Tor bundles/installation | Version:
Resolution: | Keywords: tbb dos content-
Actual Points: | type
Points: | Parent ID:
------------------------------------------+--------------------------------
Comment (by mikeperry):
This doesn't happen for me with the above link. Is it regularly
reproducible for you? Is there a test case that will always trigger it?
Based on the description, it sounds like a mime type sniffing issue. If
the mime type is not specified, Firefox will try to infer it based on
content. This code is crazy old and crufty and has experienced a number of
security issues in the past. It's also possible it has weird interactions
with super-slow networks/halted downloads due to bad Tor circuits.
Still, we have not touched that code. So whatever issues are present are
likely also in Firefox 17-ESR, and should show up there if we can get a
solid repro case. For reference, here are the official FF17.0.9 binaries:
https://ftp.mozilla.org/pub/mozilla.org/firefox/releases/17.0.9esr/
--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/9901#comment:1>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online
_______________________________________________
tor-bugs mailing list
tor-bugs@xxxxxxxxxxxxxxxxxxxx
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-bugs