New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 634557 link

Starred by 2 users

Issue metadata

Status: Fixed
Owner:
Closed: Aug 2016
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux , Android , Windows , Chrome
Pri: 1
Type: Bug-Security



Sign in to add a comment

Security: Blob file entries aren't checked against security policy

Project Member Reported by dmu...@chromium.org, Aug 5 2016

Issue description

During a refactor we accidentally removed this check:
https://codereview.chromium.org/1234813004/diff/1030001/content/browser/fileapi/fileapi_message_filter.cc

VULNERABILITY DETAILS
Previously we checked if any file item added to a blob was in the security polity for that process. We removed this in refactor. This adds it back.

VERSION
Chrome Version: 51.0.2695.0
Operating System: all

 
Components: Blink>FileAPI
Labels: Security_Severity-Medium Security_Impact-Stable
dmurph: could you please expand on the impact of this so we can update the severity? You can take a look at the severity guidelines here: https://www.chromium.org/developers/severity-guidelines

Thanks!
Project Member

Comment 2 by sheriffbot@chromium.org, Aug 5 2016

Labels: M-53
Project Member

Comment 3 by sheriffbot@chromium.org, Aug 5 2016

Labels: -Pri-0 Pri-1
Cc: edisont@google.com

Comment 6 by dmu...@chromium.org, Aug 15 2016

Labels: Merge-Request-52 Merge-Request-53

Comment 7 by dmu...@chromium.org, Aug 15 2016

Since this is a security issue for file reading, we need a merge to beta and stable.

Comment 8 by dimu@chromium.org, Aug 15 2016

Labels: -Merge-Request-52 Merge-Review-52 Hotlist-Merge-Review
[Automated comment] Request affecting a post-stable build (M52), manual review required.

Comment 9 by dimu@chromium.org, Aug 15 2016

Labels: -Merge-Request-53 Merge-Approved-53 Hotlist-Merge-Approved
Your change meets the bar and is auto-approved for M53 (branch: 2785)
Please merge your change by today 5:00 PM PT so we can take it in for this week Beta release. Thank you.
Project Member

Comment 12 by sheriffbot@chromium.org, Aug 16 2016

Status: Fixed (was: Assigned)
Please mark security bugs as fixed as soon as the fix lands, and before requesting merges. This update is based on the merge- labels applied to this issue. Please reopen if this update was incorrect.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 13 by sheriffbot@chromium.org, Aug 17 2016

Labels: -Restrict-View-SecurityTeam Restrict-View-SecurityNotify
Cc: awhalley@chromium.org
Labels: -Merge-Review-52
+awhalley as FYI.

No more M52 releases planned AFAIK and this is only a security severity medium, so I'm rejecting the merge; holler if you have any concerns.
Labels: Release-0-M53
Labels: CVE-2016-5167
Project Member

Comment 17 by sheriffbot@chromium.org, Nov 22 2016

Labels: -Restrict-View-SecurityNotify allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Labels: CVE_description-submitted
Components: Blink>Storage>FileAPI
Components: -Blink>FileAPI

Sign in to add a comment