New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 596354 link

Starred by 1 user

Issue metadata

Status: Fixed
Owner:
Closed: Mar 2016
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Mac
Pri: 1
Type: Bug



Sign in to add a comment

IMG files are not checked on Mac OS

Reported by resea...@nightwatchcybersecurity.com, Mar 21 2016

Issue description

VERSION
Chrome Version: 49.0.2623.87 Official Build
Operating System: Mac OS X El Capitan, version 10.11.3

REPRODUCTION CASE
IMG files are not checked by download protection on Mac OS. Problem is that you can take any DMG file and renamed it as an IMG file and serve it that way. Mac OS will treat both the same. To replicate this issue, take any DMG file, stick it on a web server, and renamed to an IMG. Then download on Mac and double click. It will act the same way as a DMG

We will be providing a patch as well.
 
attaching patch
img.patch
1.9 KB Download
Project Member

Comment 2 by ClusterFuzz, Mar 21 2016

Status: Assigned (was: New)
Cc: rsesek@chromium.org
Labels: Pri-1
Thanks for the report!

rsesek -- Can you corroborate this?  And are the other types we should be checking on Mac?  Thanks

Comment 4 by rsesek@chromium.org, Mar 21 2016

Yes, we only check .dmg files at the moment. I don't think the patch in #1 is complete, since it doesn't look like the file will be scanned by the DMG analyzer.
We are attaching a more complete patch covering the analyzer.

HOWEVER, there are some internal differences in formats between the two (IMG is Mac OS 9 and lower), so we are not sure whether the DMG analyzer will work on all IMG files. 
second.patch
2.7 KB Download
We did some more digging, and it looks like the same issue happens if you rename a DMG file to .ISO and .SMI. Should we file a separate bug for those, or update this one, and make a new patch?
Let's keep it in this bug, since they're different classes of the same thing.

Comment 8 by mea...@chromium.org, Mar 21 2016

Labels: Security_Impact-Stable Security_Severity-Low
We are adding a patch for IMG, ISO and SMI files. For ISO specifically, it is already checked, but this patch adds it to the DMZ analyzer as well.

Does this report qualify for VRP?
third.patch
3.6 KB Download
Yes, it qualifies.  Congrats! And thank you for the excellent patch.  I have a CL with it pending.  I'll get the appropriate labels attached here shortly.
Status: Fixed (was: Assigned)
@nparker - How do we claim the VRP?
Cc: timwillis@chromium.org
This bug will go through our VRP review board to decide on the reward.  I should have more info by Friday.
Labels: M-51
We found two additional extensions that exhibit similar behavior. Should we file a new bug?
@nparker - any news on VRP?

Also, what should we do about the two new extensions?
additional extensions filed as a bug here:
https://bugs.chromium.org/p/chromium/issues/detail?id=600613
Labels: reward-to-sb-panel OS-Mac
Labels: Type-Bug

Comment 21 by vakh@chromium.org, Apr 11 2016

Labels: -reward-to-sb-panel reward-3500

Comment 22 by vakh@chromium.org, Apr 11 2016

Labels: -reward-3500 reward-1500
How do we claim VRP?
The ball is in our court -- we will contact you as part of a weekly sweep of VRP bugs.
@nparker - what about other SafeBrowsing bugs we submitted?
Cc: vakh@chromium.org
Those are in our triage queue. They will eventually have a reward-{$$, ineligible} label or will be marked WontFix.

Comment 27 by vakh@chromium.org, Apr 18 2016

research@nightwatchcybersecurity.com: I'm sorry for the delay in triaging those bugs but I will try to do that this week. Thanks again for submitting them.

Comment 28 by vakh@chromium.org, Apr 25 2016

Labels: reward-unpaid
I just realized that I had not applied one label due to which this reward did not get paid in the current cycle. Adding it now. Sorry for the delay in getting the reward out.
No problem and thank you
Does VRP for this include the patch or do we need to email patch rewards separately?

Comment 31 by vakh@chromium.org, Apr 26 2016

It does include the reward for the patch.
@vakh@chromium.org - thank you. We still have about 4 open SB bugs, are these going to be looked at also?

Thanks
Labels: -reward-unpaid reward-inprocess
Thanks again for your report.

Someone from our finance team should get in contact within 7 days to collect payment details. If that doesn't happen, please contact me directly at timwillis@ or update this bug.
Labels: -Restrict-View-Google
Cc: ya...@nightwatchcybersecurity.com

Comment 36 by vakh@chromium.org, Mar 10 2017

Labels: Restrict-View-SecurityTeam
For all Download Protection VRP bugs: removing label Restrict-View-Google and adding Restrict-View-SecurityTeam instead.
Project Member

Comment 37 by sheriffbot@chromium.org, Mar 11 2017

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment