New issue
Advanced search Search tips

Issue 682674 link

Starred by 1 user

Issue metadata

Status: Duplicate
Owner: ----
Closed: Feb 2017
Components:
EstimatedDays: ----
NextAction: ----
OS: Windows
Pri: ----
Type: Bug



Sign in to add a comment

Google Finance My Portfolio Performance button causes Page Unresponsive dialog

Reported by mail.den...@gmail.com, Jan 19 2017

Issue description

This template is ONLY for reporting security bugs. If you are reporting a
Download Protection Bypass bug, please use the "Security - Download
Protection" template. For all other reports, please use a different
template.

Please READ THIS FAQ before filing a bug: https://www.chromium.org/Home
/chromium-security/security-faq

Please see the following link for instructions on filing security bugs:
http://www.chromium.org/Home/chromium-security/reporting-security-bugs

NOTE: Security bugs are normally made public once a fix has been widely
deployed.

VULNERABILITY DETAILS
Open https://www.google.com/finance/ and click My Portfolio to add a custom portfolio, such as FEYE, then click Performance again, and select one of the options for Dow Jones, S & P 500, Nasdaq , The entire finance page crashes.

VERSION
Chrome Version: [56.0.2902.0] + [stable, beta, or dev]
Operating System: [Win7 x64 sp1]

REPRODUCTION CASE
Please include a demonstration of the security bug, such as an attached
HTML or binary file that reproduces the bug when loaded in Chrome. PLEASE
make the file as small as possible and remove any content not required to
demonstrate the bug.

FOR CRASHES, PLEASE INCLUDE THE FOLLOWING ADDITIONAL INFORMATION
Type of crash: [tab, browser, etc.]
Crash State: [see link above: stack trace, registers, exception record]
Client ID (if relevant): [see link above]

 
demo.zip
488 KB Download
VULNERABILITY DETAILS
Open https://www.google.com/finance/ and click My Portfolio to add a custom portfolio, such as FEYE, then click Performance again, and select one of the options for Dow Jones, S & P 500, Nasdaq , The entire finance page crashes.

VERSION
Chrome Version: [56.0.2902.0] + [stable, beta, or dev]
Operating System: [Win7 x64 sp1]
Labels: Needs-Feedback
Can you please open chrome://crashes and copy the "Server ID" field of the crash report into this bug?
Components: Internals>Plugins>Flash
Labels: -Type-Bug-Security -Restrict-View-SecurityTeam OS-Windows Type-Bug
Summary: Google Finance My Portfolio Performance button causes Page Unresponsive dialog (was: Security: Google Finance My Portfolio Performance button crashes.)
Crash ID 2151cd1c-2e86-4c5a-890d-b7c7149ad57c

Crash report captured on Friday, January 20, 2017 at 11:41:51 PM (upload requested by user, not yet uploaded)

Crash ID 6da040d3-14be-4dd3-bfc4-1974600b55f8

Crash report captured on Friday, January 20, 2017 at 11:39:59 PM (upload requested by user, not yet uploaded)

Crash ID 0fe46172-e2c7-4bb3-8883-5e47f3066288

Crash report captured on Friday, January 20, 2017 at 11:37:02 PM (upload requested by user, not yet uploaded)


Crash.zip
267 KB Download
Well, it crashes the message has been screenshots, is the attachment that looks like, causing the entire Google Finance reload.

Comment 6 by ajha@chromium.org, Jan 24 2017

Labels: Needs-Triage-M56
Project Member

Comment 7 by sheriffbot@chromium.org, Jan 31 2017

Labels: -Needs-Feedback Needs-Review
Owner: elawrence@chromium.org
Thank you for providing more feedback. Adding requester "elawrence@chromium.org" for another review and adding "Needs-Review" label for tracking.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Labels: -Needs-Review Needs-Feedback
Thanks. Can you please reload the chrome://crashes page and copy into this bug the "Server ID" fields? They should appear where the text "upload requested by user, not yet uploaded" appears in Comment #4 above.
Owner: ----
Crash ID e1daab6f-b023-4e4d-ad98-7c351d0a2d78 (Server ID: 15ed88cc80000000)

Automatically reported Saturday, February 4, 2017 at 9:44:42 PM

Provide additional details


Crash ID c7b14e37-8cea-4dd5-8281-e2041f391c1a (Server ID: cb98cb6980000000)

Automatically reported Saturday, February 4, 2017 at 9:45:55 PM

Provide additional details

Crash ID ee20da8d-7d89-4982-9dfa-d6be95223bdd (Server ID: 75c54b6980000000)

Automatically reported Saturday, February 4, 2017 at 9:45:09 PM

Provide additional details

Crash ID e1daab6f-b023-4e4d-ad98-7c351d0a2d78 (Server ID: 15ed88cc80000000)

Automatically reported Saturday, February 4, 2017 at 9:44:42 PM

Provide additional details


I'm sorry, I forgot to restore the crash report, and now I have recovered the crash report.

I am Chinese, this time to go home for the Spring Festival, I'm sorry, so you wait for a long time.
Project Member

Comment 13 by sheriffbot@chromium.org, Feb 13 2017

Labels: -Needs-Feedback Needs-Review
Owner: elawrence@chromium.org
Thank you for providing more feedback. Adding requester "elawrence@chromium.org" for another review and adding "Needs-Review" label for tracking.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Labels: -Needs-Review
Owner: ----
The latter two server ID's show hangs in the Pepper Flash player and need triage by someone familiar with that code. 

(The first ServerID is an unrelated issue in updating the Windows JumpList entries.)
Is there anything else that can help you?
Mergedinto: 386371
Status: Duplicate (was: Unconfirmed)
Seems stack trace is similar to the issue#386371, hence merging this issue.
Please feel free to undup if this issue is not similar.
Thank you.

Sign in to add a comment