Issue metadata
Sign in to add a comment
|
libxml2 - Heap Overflow in xmlMemStrdupLoc
Reported by
pranjal....@gmail.com,
May 14 2017
|
||||||||||||||||||||||
Issue descriptionUserAgent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/57.0.2987.133 Safari/537.36 Steps to reproduce the problem: Gnome bugzilla's security issues are not restricted, so creating a bug here. While allocating memory for p, p = (MEMHDR *) malloc(RESERVE_SIZE+size); RESERVE_SIZE+size can wrap-around if size is greater than SIZE_MAX - RESERVE_SIZE causing a heap overflow while copying str into s strcpy(s,str); Patch attached. What is the expected behavior? What went wrong? Heap Overflow. Did this work before? N/A Chrome version: 57.0.2987.133 Channel: n/a OS Version: Flash Version:
,
May 15 2017
,
May 16 2017
I didn't create a gnome bugzilla because security bugs are not restricted. Exploitation of this issue might be difficult but I just wanted to err on the safe side. I don't have a reproducer yet. I'll update this report as soon as I'm able to come up with one.
,
May 22 2017
You can file a blank upstream bug and ask for it to be restricted. Please CC dominicc@chromium.org on these bugs. Thanks!
,
May 25 2017
,
May 30 2017
I think we have work to do for these sort of bugs so let's not make these ExternalDependency. This is just NeedsFeedback as usual.
,
May 30 2017
,
Jun 9 2017
,
Jun 9 2017
Fixed with the following commit: https://git.gnome.org/browse/libxml2/commit/?id=897dffbae322b46b83f99a607d527058a72c51ed
,
Jun 13 2017
dominicc: Uh oh! This issue still open and hasn't been updated in the last 14 days. This is a serious vulnerability, and we want to ensure that there's progress. Could you please leave an update with the current status and any potential blockers? If you're not the right owner for this issue, could you please remove yourself as soon as possible or help us find the right one? If the issue is fixed or you can't reproduce it, please close the bug. If you've started working on a fix, please set the status to Started. Thanks for your time! To disable nags, add the Disable-Nags label. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Jun 14 2017
OK, apparently we need to roll libxml2.
,
Jun 14 2017
Patch up for review at https://chromium-review.googlesource.com/c/535233/
,
Jul 13 2017
We commit ourselves to a 60 day deadline for fixing for high severity vulnerabilities, and have exceeded it here. If you're unable to look into this soon, could you please find another owner or remove yourself so that this gets back into the security triage queue? For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Sep 6 2017
,
Sep 19 2017
dominicc: I see that CL in #12 was landed. Can this be marked as fixed now?
,
Sep 26 2017
,
Sep 27 2017
,
Sep 27 2017
,
Oct 6 2017
Hi pranjal.jumde@ - the Chrome VRP Panel declined to reward for this bug, but noted they would take another look if you could illustrate how it could be exploited via Chrome. However, you might want to look at https://www.google.com/about/appsecurity/patch-rewards/ since you provided a security relevant patch that was used. Cheers!
,
Oct 6 2017
It would be hard to exploit this one, I am not looking for a reward but just wanted this issue to be addressed. Do you plan to release a CVE for this?
,
Oct 11 2017
Thanks pranjal.jumde@, - yep, this should get a CVE allocated when M62 goes stable in the next few weeks. Cheers!
,
Oct 16 2017
,
Oct 18 2017
,
Oct 27 2017
,
Oct 27 2017
This bug requires manual review: M63 has already been promoted to the beta branch, so this requires manual review Please contact the milestone owner if you have questions. Owners: cmasso@(Android), cmasso@(iOS), gkihumba@(ChromeOS), govind@(Desktop) For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Oct 27 2017
+awhalley@ (Security TPM) for M63 merge review
,
Oct 30 2017
No merge needed, not sure why sheriffbot thought differently
,
Jan 3 2018
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Feb 28 2018
Issue 816860 has been merged into this issue.
,
Apr 25 2018
|
|||||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||||
Comment 1 by aarya@google.com
, May 15 2017Owner: dominicc@chromium.org