[tor-bugs] #9901 [TorBrowserButton]: DoS of TBB 2.4/3.0 when no Content-Type header and more than 512 bytes of content are sent

Tor Bug Tracker & Wiki blackhole at torproject.org
Fri Jan 10 16:49:21 UTC 2014


#9901: DoS of TBB 2.4/3.0 when no Content-Type header and more than 512 bytes of
content are sent
----------------------------------+----------------------------------
     Reporter:  sqrt2             |      Owner:  mikeperry
         Type:  defect            |     Status:  new
     Priority:  normal            |  Milestone:
    Component:  TorBrowserButton  |    Version:
   Resolution:                    |   Keywords:  tbb dos content-type
Actual Points:                    |  Parent ID:
       Points:                    |
----------------------------------+----------------------------------

Comment (by adrian.halston):

 Experienced what seems to be this bug in TBB 3.5 with the following URL:

 http://gkall.hobby.nl/cism216.fw

 It does not occur in Firefox ESR (the same version as TBB 3.5 uses).
 Occurs on both Linux and Windows.  Checked with Wireshark that no Content-
 Type header is sent.

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/9901#comment:12>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list