Issue metadata
Sign in to add a comment
|
Security: Chrome crashes after 500 thousand lines to a few million lines of malformed url strings
Reported by
kingz...@gmail.com,
Jan 16 2017
|
||||||||||||||||||
Issue descriptionVULNERABILITY DETAILS Please provide a brief explanation of the security issue. VERSION Chrome Version: Version 55.0.2883.87 m stable Operating System: Windows 10 Home REPRODUCTION CASE When a user provides a malformed string, such as http://example.com//example.com/ and repeats it for 500 thousand characters or more the Chrome browser hangs and then Chrome shuts down completely killing all of it's processes and is unable to restore the previous tabs when it is restarted. This attack does not work if the website has cloudflare since they blocked it after we tested it too many times. Also, certain server configurations refuse to accept the malformed url, but after one million characters the site will either lead to the browser crashing or stop responding. If it stops responding and gives no error then a few more million lines should make the browser crash. We have reproduced this bug multiple times. We were going to try and gain control of memory, but your rules say to report early, instead of later. If you have any questions or need help reproducing, since example.com may not reproduce the issue, we will be happy to assist and if we can find the area that has the flaw we will see if we can write a patch as well. FOR CRASHES, PLEASE INCLUDE THE FOLLOWING ADDITIONAL INFORMATION Type of crash: Chrome, any tab, requires interaction with a server unless it freezes because there is too much text in the browser url address. Crash State:
,
Jan 17 2017
Yes I will. As noted some servers have proper protection against malformed urls that the browser can't parse, others do not. I will find a domain without proper protection to test on.
,
Jan 17 2017
There are several ways to hang a browser and this is not in security threat model. https://www.chromium.org/Home/chromium-security/security-faq#TOC-Are-denial-of-service-issues-considered-security-bugs-
,
Jan 17 2017
I am aware of your denial of service rules and wouldn't be filing this if it didn't actually crash, not just a denial of service. If you aren't interested I'll stop reporting on this thread.
,
Apr 25 2017
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
|||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||
Comment 1 by kerrnel@chromium.org
, Jan 17 2017