New issue
Advanced search Search tips
Starred by 3 users

Issue metadata

Status: WontFix
Owner: ----
Closed: Feb 2013
EstimatedDays: ----
NextAction: ----
OS: Windows
Pri: 0
Type: Bug-Security

Restricted
  • Only users with EditIssue permission may comment.



Sign in to add a comment
link

Issue 130284: Security: disabled.DLL is susceptible to library hijack attack

Reported by zimo...@gmail.com, May 30 2012

Issue description

VULNERABILITY DETAILS
disabled.dll is susceptible to library hijack.

VERSION
Chrome Version: 19.0.1084.52 m stable
OS Name:        Microsoft Windows 7 Enterprise
OS Version:     6.1.7601 Service Pack 1 Build 7601

REPRODUCTION CASE
For actual reproduction all you need to do is to run chrome.exe.

To notice the finding follow those steps:
(1) Capture events using sysinternals' procmon.exe
(2) Run chrome.exe, wait for completion
(3) Under procmon - Filter according to Path that contains disabled.DLL

FOR CRASHES, PLEASE INCLUDE THE FOLLOWING ADDITIONAL INFORMATION
Type of crash: none
 

Comment 1 by jsc...@chromium.org, May 30 2012

Status: Invalid
If you have permission to write arbitrary DLLs to these paths then you have sufficient permission to replace the Chrome install or other essential binaries.

Comment 2 by zimo...@gmail.com, May 31 2012

That's not correct. The DLL is loaded by an old-school search function that traverses the PATH environmental variable, and its components are determined on every computer system individually.

Comment 3 by bugdroid1@chromium.org, Oct 13 2012

Project Member
Labels: Restrict-AddIssueComment-Commit
This issue has been closed for some time. No one will pay attention to new comments.
If you are seeing this bug or have new data, please click New Issue to start a new bug.

Comment 4 by bugdroid1@chromium.org, Feb 27 2013

Project Member
Labels: status_migrated
Status: WontFix

Comment 5 by bugdroid1@chromium.org, Mar 10 2013

Project Member
Labels: -Type-Security Type-Bug-Security

Comment 6 by bugdroid1@chromium.org, Mar 11 2013

Project Member
Labels: -Area-Undefined

Comment 7 by bugdroid1@chromium.org, Mar 13 2013

Project Member
Labels: Restrict-View-EditIssue

Comment 8 by wfh@chromium.org, Jun 7 2013

Labels: -Restrict-View-SecurityTeam -status_migrated OS-Windows

Comment 9 by wfh@chromium.org, Jun 7 2013

Labels: -Restrict-AddIssueComment-Commit -Restrict-View-EditIssue Restrict-AddIssueComment-EditIssue

Comment 10 by sheriffbot@chromium.org, Oct 1 2016

Project Member
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Comment 11 by sheriffbot@chromium.org, Oct 2 2016

Project Member
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Comment 12 by mbarbe...@chromium.org, Oct 2 2016

Labels: allpublic

Comment 13 by elawrence@chromium.org, Aug 20 2017

 Issue 757193  has been merged into this issue.

Sign in to add a comment