New issue
Advanced search Search tips

Issue 130284 link

Starred by 3 users

Issue metadata

Status: WontFix
Owner: ----
Closed: Feb 2013
EstimatedDays: ----
NextAction: ----
OS: Windows
Pri: 0
Type: Bug-Security

Restricted
  • Only users with EditIssue permission may comment.



Sign in to add a comment

Security: disabled.DLL is susceptible to library hijack attack

Reported by zimo...@gmail.com, May 30 2012

Issue description

VULNERABILITY DETAILS
disabled.dll is susceptible to library hijack.

VERSION
Chrome Version: 19.0.1084.52 m stable
OS Name:        Microsoft Windows 7 Enterprise
OS Version:     6.1.7601 Service Pack 1 Build 7601

REPRODUCTION CASE
For actual reproduction all you need to do is to run chrome.exe.

To notice the finding follow those steps:
(1) Capture events using sysinternals' procmon.exe
(2) Run chrome.exe, wait for completion
(3) Under procmon - Filter according to Path that contains disabled.DLL

FOR CRASHES, PLEASE INCLUDE THE FOLLOWING ADDITIONAL INFORMATION
Type of crash: none

 

Comment 1 by jsc...@chromium.org, May 30 2012

Status: Invalid
If you have permission to write arbitrary DLLs to these paths then you have sufficient permission to replace the Chrome install or other essential binaries.

Comment 2 by zimo...@gmail.com, May 31 2012

That's not correct. The DLL is loaded by an old-school search function that traverses the PATH environmental variable, and its components are determined on every computer system individually.
Project Member

Comment 3 by bugdroid1@chromium.org, Oct 13 2012

Labels: Restrict-AddIssueComment-Commit
This issue has been closed for some time. No one will pay attention to new comments.
If you are seeing this bug or have new data, please click New Issue to start a new bug.
Project Member

Comment 4 by bugdroid1@chromium.org, Feb 27 2013

Labels: status_migrated
Status: WontFix
Project Member

Comment 5 by bugdroid1@chromium.org, Mar 10 2013

Labels: -Type-Security Type-Bug-Security
Project Member

Comment 6 by bugdroid1@chromium.org, Mar 11 2013

Labels: -Area-Undefined
Project Member

Comment 7 by bugdroid1@chromium.org, Mar 13 2013

Labels: Restrict-View-EditIssue

Comment 8 by wfh@chromium.org, Jun 7 2013

Labels: -Restrict-View-SecurityTeam -status_migrated OS-Windows

Comment 9 by wfh@chromium.org, Jun 7 2013

Labels: -Restrict-AddIssueComment-Commit -Restrict-View-EditIssue Restrict-AddIssueComment-EditIssue
Project Member

Comment 10 by sheriffbot@chromium.org, Oct 1 2016

This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 11 by sheriffbot@chromium.org, Oct 2 2016

This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Labels: allpublic
 Issue 757193  has been merged into this issue.

Sign in to add a comment