Security: Heap buffer overflows from unchecked payload_size in mojo::edj::BrokerHost::OnChannelMessage |
||||||||||||||
Issue descriptionmojo::edk::BrokerHost::OnChannelMessage has similar issues to the previously reported bugs -- |payload| is derefed and used without checking |payload_size|.
,
May 18 2016
,
May 18 2016
Adding Merge-Triage label for tracking purposes. Once your fix had sufficient bake time (on canary, dev as appropriate), please nominate your fix for merge by adding the Merge-Request-XX label, where XX is the Chrome milestone. When your merge is approved by the release manager, please start merging with higher milestone label first. Make sure to re-request merge for every milestone in the label list. You can get branch information on omahaproxy.appspot.com. Your fix is very close to the branch point. After the branch happens, please make sure to check if your fix is in. - Your friendly ClusterFuzz
,
May 18 2016
,
May 21 2016
,
May 21 2016
[Automated comment] Less than 2 weeks to go before stable on M51, manual review required.
,
May 23 2016
Is this bug applicable to specific OS or all os? Also before we approve merge to M51, Could you please confirm whether this change is baked/verified in Canary and safe to merge?
,
May 23 2016
,
May 23 2016
The change is baked, verified, and safe to merge. It applies to Linux, Chrome OS, Android, and Mac. Does not affect Windows.
,
May 23 2016
Approving merge to M51 branch 2704 based on comment #9. Please merge before 5:00 PM PST today (Monday) in order to make it to M51 Desktop Stable cut. Thank you.
,
May 23 2016
The following revision refers to this bug: https://chromium.googlesource.com/chromium/src.git/+/4fcb6e3ec5ca9b16e584f7c54bd8c163c302e2ca commit 4fcb6e3ec5ca9b16e584f7c54bd8c163c302e2ca Author: Ken Rockot <rockot@chromium.org> Date: Mon May 23 17:47:48 2016 [mojo-edk] Fix potential buffer overflow in BrokerHost BUG= 612613 R=ochang@chromium.org Review-Url: https://codereview.chromium.org/1983363002 Cr-Commit-Position: refs/heads/master@{#394303} (cherry picked from commit 6c167254182506e10fe2fa9fa24d233da620b204) Review URL: https://codereview.chromium.org/2001213002 . Cr-Commit-Position: refs/branch-heads/2704@{#635} Cr-Branched-From: 6e53600def8f60d8c632fadc70d7c1939ccea347-refs/heads/master@{#386251} [modify] https://crrev.com/4fcb6e3ec5ca9b16e584f7c54bd8c163c302e2ca/mojo/edk/system/broker_host_posix.cc
,
May 23 2016
,
Aug 24 2016
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Oct 1 2016
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Oct 2 2016
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Oct 2 2016
,
Jul 28
|
||||||||||||||
►
Sign in to add a comment |
||||||||||||||
Comment 1 by bugdroid1@chromium.org
, May 18 2016