New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 617149 link

Starred by 2 users

Issue metadata

Status: Fixed
Owner:
Last visit > 30 days ago
Closed: Jan 2018
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: 1
Type: Bug-Security

Blocking:
issue 62400



Sign in to add a comment

Security: libtiff in pdfium may have a security issue

Reported by resea...@nightwatchcybersecurity.com, Jun 3 2016

Issue description

Comment 1 by f...@chromium.org, Jun 3 2016

Components: Infra>Client>Pdfium
Owner: och...@chromium.org
Status: Untriaged (was: Unconfirmed)
ochang@, it looks like CVE-2015-7554 was reported for libtiff 4.0.6, but it hasn't been patched so it would still exist in the version used by pdfium.
Labels: -Restrict-View-SecurityTeam
Since it's a public CVE, I'm removing the view restrictions.

There appear to be no patches for this though, and I'm not familiar enough with tiff to make a confident judgement about whether this actually affects pdfium, or to write a correct patch for it...

Components: Internals>Plugins>PDF
Components: -Infra>Client>Pdfium
Cc: och...@chromium.org
Owner: hong_zh...@foxitsoftware.com
Status: Assigned (was: Untriaged)
hong_zhang, could you please route this security bug to the appropriate person? thanks.
Project Member

Comment 7 by ClusterFuzz, Jun 7 2016

Labels: Missing_Severity-1 Missing_Impact-1
Labels: -Missing_Impact-1 Security_Impact-Head
I will. ochange@
Additional CVEs with buffer overflows:

CVE-2016-5318
CVE-2016-5319 

Details:
http://www.openwall.com/lists/oss-security/2016/06/07/1
Labels: Security_Severity-High
Marking this severity-high because at least one (CVE-2015-8668) of these CVEs is a buffer overflow.
Project Member

Comment 12 by sheriffbot@chromium.org, Jun 10 2016

Labels: M-53
Project Member

Comment 13 by sheriffbot@chromium.org, Jun 10 2016

Labels: ReleaseBlock-Beta
This issue is a security regression. If you are not able to fix this quickly, please revert the change that introduced it.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 14 by sheriffbot@chromium.org, Jun 10 2016

Labels: Pri-1
Blocking: 62400
Labels: -Security_Impact-Head Security_Impact-None
Labels: -M-53 M-52
Labels: Needs-Feedback
Can you please add the OS label which was affected ?

Also, please let us know if this can be tested manually.

This is marked as M52 RB-Beta label, hence requesting you to provide you the details so that this can be fixed & merged in to M52 branch for next beta promotion this wednesday.
Labels: -ReleaseBlock-Beta -Needs-Feedback
Removing the release block label -- there was no demonstrated reachable vulnerability in this bug report, and the feature in question that uses this library has already been turned off.
Blocking:
Cc: ya...@nightwatchcybersecurity.com
Status: Fixed (was: Assigned)
We have since updated libtiff to 4.0.8, which I believe has this issue fixed.
Project Member

Comment 23 by sheriffbot@chromium.org, Feb 8 2018

Labels: Restrict-View-SecurityNotify
Project Member

Comment 24 by sheriffbot@chromium.org, May 10 2018

Labels: -Restrict-View-SecurityNotify allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Labels: reward-topanel
Labels: -reward-topanel reward-0
(the VRP panel declined to award, see comment 19)

Sign in to add a comment