New issue
Advanced search Search tips

Issue 618948 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner: ----
Closed: Jun 2016
EstimatedDays: ----
NextAction: ----
OS: ----
Pri: ----
Type: Bug-Security



Sign in to add a comment

Security: Write AV crash in Vivaldi Browser (1/4)

Reported by 610c...@gmail.com, Jun 10 2016

Issue description

VULNERABILITY DETAILS
described as an output from windbg in details.txt (attached).

VERSION
Vivaldi Browser 1.2 (vivaldi.net)
Operating System: Windows 7 (32bit)

REPRODUCTION CASE
vivaldi.exe poc.swf

Type of crash: Write Access Violation
Crash State: in details.txt

P.S. I'm sending this directly to you because:
"(...)With regards to the other issues, even if they are indeed valid in some scenarios, they are very likely to be deep within Chromium or Blink code that we have not altered. Therefore these issues should really be reported upstream to the Chromium project. Thus if there is indeed anything exploitable, fixes will end up in all Chromium derived browsers and products, thus benefiting the widest range of users."



 
poc1-vivaldi1.2-UserWriteAccess.zip
3.9 MB Download

Comment 1 by 610c...@gmail.com, Jun 10 2016

To not create too many posts, below you will find another poc for SWF crash. Similar scenario: vivaldi.exe poc2.swf -> WriteAV.
poc-2-swf-vivaldi.1.2-04.06.2016.zip
1.3 MB Download

Comment 2 by 610c...@gmail.com, Jun 10 2016

3rd: (gmail said its a "virus", so password is: 0xdefc5219.0x22b71bb3)

This time poc in TIFF format (WriteAV again).
password--is--0xdefc5219.0x22b71bb3--poc-3-tiff-vivaldi.1.2-04.06.2016-0xdefc5219.0x22b71bb3.zip
29.3 KB Download

Comment 3 by 610c...@gmail.com, Jun 10 2016

Last write AV poc, TIFF too - below.
poc-4-tiff-vivaldi.1.2-04.06.20160xe729c745.0x8f65db43.zip
29.0 KB Download

Comment 4 by 610c...@gmail.com, Jun 10 2016

In my opinion, the last one (GIF poc) is a DoS,
but maybe you will find it useful.


0xfc51b4ad.0x4d6f0d80.zip
14.5 KB Download
Project Member

Comment 5 by ClusterFuzz, Jun 10 2016

ClusterFuzz is analyzing your testcase. Developers can follow the progress at https://cluster-fuzz.appspot.com/testcase?key=5345774556938240
Project Member

Comment 6 by ClusterFuzz, Jun 10 2016

ClusterFuzz is analyzing your testcase. Developers can follow the progress at https://cluster-fuzz.appspot.com/testcase?key=4755260040282112
Project Member

Comment 7 by ClusterFuzz, Jun 10 2016

ClusterFuzz is analyzing your testcase. Developers can follow the progress at https://cluster-fuzz.appspot.com/testcase?key=5619197090725888
Project Member

Comment 8 by ClusterFuzz, Jun 10 2016

ClusterFuzz is analyzing your testcase. Developers can follow the progress at https://cluster-fuzz.appspot.com/testcase?key=6656746030628864
Project Member

Comment 9 by ClusterFuzz, Jun 10 2016

ClusterFuzz is analyzing your testcase. Developers can follow the progress at https://cluster-fuzz.appspot.com/testcase?key=5618724442996736
Project Member

Comment 10 by ClusterFuzz, Jun 10 2016

ClusterFuzz is analyzing your testcase. Developers can follow the progress at https://cluster-fuzz.appspot.com/testcase?key=5322387654705152
Project Member

Comment 11 by ClusterFuzz, Jun 10 2016

ClusterFuzz is analyzing your testcase. Developers can follow the progress at https://cluster-fuzz.appspot.com/testcase?key=6129851925004288
Project Member

Comment 12 by ClusterFuzz, Jun 10 2016

ClusterFuzz is analyzing your testcase. Developers can follow the progress at https://cluster-fuzz.appspot.com/testcase?key=4844517329207296
Project Member

Comment 13 by ClusterFuzz, Jun 10 2016

ClusterFuzz is analyzing your testcase. Developers can follow the progress at https://cluster-fuzz.appspot.com/testcase?key=5152130671575040
Project Member

Comment 14 by ClusterFuzz, Jun 10 2016

ClusterFuzz is analyzing your testcase. Developers can follow the progress at https://cluster-fuzz.appspot.com/testcase?key=5649512765063168

Thanks for the report.  Do you have any POC that you've tested with Chrome?

(Sorry for the spam - clusterfuzz UI was failing to give a confirmation of upload.)
Status: WontFix (was: Unconfirmed)
Thanks for the report, but none of these reproduce on Chrome.  If you do narrow this down to code within chrome, and have a repro, please file another bug. Thank you.
Project Member

Comment 17 by sheriffbot@chromium.org, Sep 17 2016

Labels: -Restrict-View-SecurityTeam
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 18 by sheriffbot@chromium.org, Oct 1 2016

This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 19 by sheriffbot@chromium.org, Oct 2 2016

This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Labels: allpublic

Sign in to add a comment