New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 595561 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner:
Closed: Mar 2016
Cc:
EstimatedDays: ----
NextAction: ----
OS: Chrome
Pri: ----
Type: Bug-Security



Sign in to add a comment

Security: Top in Crosh/ChromeOS appears to being able to write files in guest mode

Reported by resea...@nightwatchcybersecurity.com, Mar 17 2016

Issue description

VULNERABILITY DETAILS
When in guest mode, the top command in Crosh appears to write files. It is unclear f /home/chronos/user persists.

VERSION
Chrome Version: 49.0.2623.95 (Official Build) (64-bit)
Operating System: ChromeOS 7834.60.0 (= Official Build) stable-channel parrot

REPRODUCTION CASE
1. Login to Chrome OS in guest mode.
2. Press CTRL-ALT-T to open crosh.
3. Type in "top" and press enter.
4. Press "W". A message will come up "file written to /home/chronos/user/.toprc"
 

Comment 1 by mea...@chromium.org, Mar 18 2016

Cc: kerrnel@chromium.org
Labels: OS-Chrome
Owner: mdempsky@chromium.org
Status: Assigned (was: Unconfirmed)
mdempsky, kerrnel: Can one of you please triage? Thanks.
Owner: kerrnel@chromium.org
I will triage this.
Status: WontFix (was: Assigned)
Thanks for the report. In guest mode, /home/chronos/user is a tmpfs mount, so marking this as "works as intended."
Project Member

Comment 4 by sheriffbot@chromium.org, Jun 28 2016

Labels: -Restrict-View-SecurityTeam
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 5 by sheriffbot@chromium.org, Oct 1 2016

This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 6 by sheriffbot@chromium.org, Oct 2 2016

This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Labels: allpublic
Cc: ya...@nightwatchcybersecurity.com

Sign in to add a comment