Closed Bug 718759 Opened 13 years ago Closed 13 years ago

Endless recursion verifying S/MIME cert from UTN-USERFirst with NSS_ENABLE_PKIX_VERIFY="1"

Categories

(NSS :: Libraries, defect)

3.13.1
x86
Linux
defect
Not set
normal

Tracking

(Not tracked)

RESOLVED DUPLICATE of bug 551429

People

(Reporter: KaiE, Unassigned)

References

Details

(Keywords: crash)

Attachments

(1 file)

Attached file debug information (deleted) —
Crash occurrs in both Thunderbird 9 and 10 (beta), both Mozilla and Fedora builds. I used Fedora excutables for tracing (easier with systemwide installed debuginfo). Using NSS 3.13.1 and environment variable NSS_ENABLE_PKIX_VERIFY="1" In Thunderbird, I click on an S/MIME signed email from cfu@rh For quite a while, everything seems fine, but in the background we have a job that attempts to verify the S/MIME signature. Eventually it crashes. I have a core file with a stack of more than 46,000 (!) levels. (Eventually it crashes elsewhere, but that clearly is a stack overflow.) I'm attaching a file with portions of the stack, and information about the involved certificates.
Blocks: pkix-default
FWIW, when running Thunderbird and NOT using PKIX_VERIFY, there is no crash. The S/MIME signature is shown as invalid. The cert hierarchy stops at level 20 (I assume the loop detection is active in this non-libpkix scenario).
Status: NEW → RESOLVED
Closed: 13 years ago
Resolution: --- → DUPLICATE
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: