New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 605477 link

Starred by 0 users

Issue metadata

Status: Duplicate
Merged: issue 610646
Owner:
Buried. Ping if important.
Closed: May 2016
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 1
Type: Bug-Security



Sign in to add a comment

Bad-cast to const blink::WebPasswordCredential from blink::WebCredential;type_converters.cc:87:9

Project Member Reported by ClusterFuzz, Apr 21 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=4975983190343680

Fuzzer: inferno_twister
Job Type: linux_ubsan_vptr_chrome
Platform Id: linux

Crash Type: Bad-cast
Crash Address: 0x7ffdff04db40
Crash State:
  Bad-cast to const blink::WebPasswordCredential from blink::WebCredential
  type_converters.cc:87:9
  
Recommended Security Severity: High


Minimized Testcase (0.11 Kb):
Download: https://cluster-fuzz.appspot.com/download/AMIfv97bgrppt32_3rkbDAfax3D6hyFuPaeGwz8g8Ucdr0tmPYPPPCU70KkRsGCDkcngC8vfIUU-lkrsCJd6WIfDXntvsTlUUxzpebPgddddmXIP-fCSzlcbwZKn1BrdeoCRRLKcwg8uNt0Vfk3nrx8r7YDi2c9R9g
<script>
navigator.credentials.store(new PasswordCredential({'id': 'name', 'password': 'password' }))
</script>


Filer: mmoroz

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 

Comment 1 by mmoroz@chromium.org, Apr 21 2016

Components: UI>Browser>Passwords
Labels: Pri-1
Owner: mkwst@chromium.org
Mike, do you mind to take a look or suggest another owner? Looks similar to  bug 590610  fixed two months ago.
Project Member

Comment 2 by ClusterFuzz, Apr 21 2016

Status: Assigned (was: Available)
Project Member

Comment 3 by sheriffbot@chromium.org, Apr 21 2016

Labels: M-52
Project Member

Comment 4 by ClusterFuzz, Apr 22 2016

Labels: ReleaseBlock-Beta
This medium+ severity security issue is a regression on trunk.

Please fix this asap. If you are unable to look into this soon, please revert your change.

- Your friendly ClusterFuzz
Project Member

Comment 5 by sheriffbot@chromium.org, May 5 2016

mkwst: Uh oh! This issue still open and hasn't been updated in the last 14 days. This is a serious vulnerability, and we want to ensure that there's progress. Could you please leave an update with the current status and any potential blockers?

If you're not the right owner for this issue, could you please remove yourself as soon as possible or help us find the right one?

If the issue is fixed or you can't reproduce it, please close the bug. If you've started working on a fix, please set the status to Started.

Thanks for your time! To disable nags, add the Disable-Nags label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 6 by sheriffbot@chromium.org, May 19 2016

mkwst: Uh oh! This issue still open and hasn't been updated in the last 28 days. This is a serious vulnerability, and we want to ensure that there's progress. Could you please leave an update with the current status and any potential blockers?

If you're not the right owner for this issue, could you please remove yourself as soon as possible or help us find the right one?

If the issue is fixed or you can't reproduce it, please close the bug. If you've started working on a fix, please set the status to Started.

Thanks for your time! To disable nags, add the Disable-Nags label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Mergedinto: 610646
Status: Duplicate (was: Assigned)
This is same stack as 610646. We just didn't realise we filed it twice. Also verified by https://cluster-fuzz.appspot.com/testcase?key=5743138161557504 since now it does not reproduce on trunk.
Project Member

Comment 8 by ClusterFuzz, May 27 2016

ClusterFuzz has detected this issue as fixed in range 392933:392978.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=4975983190343680

Fuzzer: inferno_twister
Job Type: linux_ubsan_vptr_chrome
Platform Id: linux

Crash Type: Bad-cast
Crash Address: 0x7ffdff04db40
Crash State:
  Bad-cast to const blink::WebPasswordCredential from blink::WebCredential
  type_converters.cc:87:9
  
Recommended Security Severity: High

Fixed: https://cluster-fuzz.appspot.com/revisions?job=linux_ubsan_vptr_chrome&range=392933:392978

Minimized Testcase (0.11 Kb):
Download: https://cluster-fuzz.appspot.com/download/AMIfv97bgrppt32_3rkbDAfax3D6hyFuPaeGwz8g8Ucdr0tmPYPPPCU70KkRsGCDkcngC8vfIUU-lkrsCJd6WIfDXntvsTlUUxzpebPgddddmXIP-fCSzlcbwZKn1BrdeoCRRLKcwg8uNt0Vfk3nrx8r7YDi2c9R9g
<script>
navigator.credentials.store(new PasswordCredential({'id': 'name', 'password': 'password' }))
</script>


See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 9 by sheriffbot@chromium.org, Sep 1 2016

Labels: -Restrict-View-SecurityTeam
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 10 by sheriffbot@chromium.org, Oct 1 2016

This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 11 by sheriffbot@chromium.org, Oct 2 2016

This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Labels: allpublic

Sign in to add a comment