New issue
Advanced search Search tips

Issue 662672 link

Starred by 1 user

Issue metadata

Status: WontFix
Owner: ----
Closed: Nov 2016
EstimatedDays: ----
NextAction: ----
OS: Windows
Pri: 2
Type: Bug-Security



Sign in to add a comment

INVALID_POINTER_WRITE when opening specific jpeg file

Reported by kaslovdm...@gmail.com, Nov 5 2016

Issue description

UserAgent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Ubuntu Chromium/51.0.2704.79 Chrome/51.0.2704.79 Safari/537.36

Steps to reproduce the problem:
1. attach chrome to windbg
2. open the POC jpeg
3. a crash should be observed

What is the expected behavior?

What went wrong?
I got a crash:

eax=00001258 ebx=00000000 ecx=00006e00 edx=7fff1000 esi=00001014 edi=57aa4f6f
eip=57aa4906 esp=0475d088 ebp=0475d10c iopl=0         nv up ei pl zr na pe nc
cs=0023  ss=002b  ds=002b  es=002b  fs=0053  gs=002b             efl=00210246
chrome_child+0x464906:
57aa4906 8946ec          mov     dword ptr [esi-14h],eax ds:002b:00001000=????????

Did this work before? N/A 

Chrome version: 53.0.2785.116  Channel: n/a
OS Version: 7
Flash Version:
 
chromemain.dmp
116 KB Download
sf_d10d68a5a79f3163de54194ecb82adf1-26604-0x00001000.jpg
304 bytes View Download
Project Member

Comment 1 by ClusterFuzz, Nov 7 2016

ClusterFuzz is analyzing your testcase. Developers can follow the progress at https://cluster-fuzz.appspot.com/testcase?key=4684235769380864

Comment 2 by rickyz@chromium.org, Nov 11 2016

Labels: Needs-Feedback
Hi, we have been unable to reproduce this on any current version of Chrome - can you still reproduce this on Chrome stable, or better yet, an ASAN build (downloadable from https://dev.chromium.org/developers/testing/addresssanitizer#TOC-Pre-built-Chrome-binaries)

Comment 3 by mea...@chromium.org, Nov 18 2016

Status: WontFix (was: Unconfirmed)
Closing as wontfix.

@kaslovdmitri1: Please let us know if you can still reproduce this bug on Stable channel, and we'll be happy to reopen it. Thanks.
Project Member

Comment 4 by sheriffbot@chromium.org, Feb 25 2017

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment