New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 669136 link

Starred by 1 user

Issue metadata

Status: Fixed
Owner:
Last visit > 30 days ago
Closed: Feb 2017
Components:
EstimatedDays: ----
NextAction: ----
OS: Windows
Pri: 1
Type: Bug-Security



Sign in to add a comment

Security: [FG-VD-16-086] Adobe Flash Player Handing MP4 Memory Corruption Vulnerability

Reported by kevinlu0...@gmail.com, Nov 28 2016

Issue description

VULNERABILITY DETAILS
It is a memory corruption vulnerability in MP4 processing. 

VERSION
Adobe Flash Player  23.0.0.207
Other versions may be affected too

REPRODUCTION CASE
put LoadMP42.swf and FG-VD-16-086_PoC.mp4 on a server and load http://127.0.0.1:8080/LoadMP42.swf?file=FG-VD-16-086_PoC.mp4
run the following command line.
flashplayer_23_sa_207.exe http://127.0.0.1:8080/LoadMP42.swf?file=FG-VD-16-086_PoC.mp4

Credits:
  This vulnerability was discovered by Kai Lu of Fortinet's FortiGuard Labs.
 
FG-VD-16-086_PoC.mp4
1.1 MB View Download
LoadMP42.swf
1.0 KB Download
crashlog1.txt
3.6 KB View Download
Components: Internals>Plugins>Flash
Labels: Security_Severity-High Security_Impact-Stable
Owner: natashenka@google.com
Status: Assigned (was: Unconfirmed)
+natashenka

Can you please confirm this affects the Flash player shipped with Chrome?
Labels: OS-Windows
Project Member

Comment 3 by sheriffbot@chromium.org, Nov 29 2016

Labels: M-54
Project Member

Comment 4 by sheriffbot@chromium.org, Nov 29 2016

Labels: Pri-1
Repros for me consistently on Firefox, and inconsistently on Chrome and content projector only on Windows 7. I'll report this to Adobe.
Status: ExternalDependency (was: Assigned)
This is PSIRT-6066.
Project Member

Comment 7 by sheriffbot@chromium.org, Dec 2 2016

Labels: -M-54 M-55
Project Member

Comment 8 by sheriffbot@chromium.org, Jan 26 2017

Labels: -M-55 M-56
This was fixed as CVE-2017-2990
Labels: reward-topanel
Status: Fixed (was: ExternalDependency)
Project Member

Comment 12 by sheriffbot@chromium.org, Feb 16 2017

Labels: -Restrict-View-SecurityTeam Restrict-View-SecurityNotify
Labels: -reward-topanel reward-unpaid reward-500
The panel decided to award $500 for this report - thanks!
Labels: -reward-unpaid reward-inprocess

Comment 16 Deleted

Comment 17 Deleted

Project Member

Comment 18 by sheriffbot@chromium.org, Feb 18 2017

Labels: Merge-Request-57
Project Member

Comment 19 by sheriffbot@chromium.org, Feb 19 2017

Labels: -Merge-Request-57 Hotlist-Merge-Approved Merge-Approved-57
Your change meets the bar and is auto-approved for M57. Please go ahead and merge the CL to branch 2987 manually. Please contact milestone owner if you have questions.
Owners: amineer@(clank), cmasso@(bling), ketakid@(cros), govind@(desktop)

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Labels: -Merge-Approved-57 Merge-Rejected-57
No merge needed.
Labels: -Hotlist-Merge-Approved
Project Member

Comment 22 by sheriffbot@chromium.org, May 25 2017

Labels: -Restrict-View-SecurityNotify allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment