New issue
Advanced search Search tips

Issue 726680 link

Starred by 1 user

Issue metadata

Status: Duplicate
Merged: issue 707549
Owner: ----
Closed: May 2017
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux , Windows
Pri: 1
Type: Bug-Security



Sign in to add a comment

Iframe print UaF

Reported by wadih.ma...@gmail.com, May 26 2017

Issue description

UserAgent: Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.36

Steps to reproduce the problem:
1. open http://localhost/poc.html
2. crash

What is the expected behavior?
Print should occur normally 

What went wrong?
The iframe that triggered the print is removed during the print: PrintWebViewHelper::PrintPageInternal works on a freed frame => UaF (see stacktrace.txt)

Did this work before? N/A 

Chrome version: 58.0.3029.110  Channel: stable
OS Version: 6.1 (Windows 7, Windows Server 2008 R2)
Flash Version:
 
poc.zip
3.6 KB Download
Components: Internals>Printing
Project Member

Comment 2 by ClusterFuzz, May 26 2017

ClusterFuzz is analyzing your testcase. Developers can follow the progress at https://cluster-fuzz.appspot.com/testcase?key=6319967489490944

Comment 3 by kenrb@chromium.org, May 26 2017

Labels: -Pri-2 Security_Severity-High Security_Impact-Stable M-59 OS-Linux Pri-1
Status: Untriaged (was: Unconfirmed)
Thanks for the report, I have confirmed this locally on Stable, and it does look like a UaF. I'm checking if ClusterFuzz can give more details before triaging.

Comment 4 by kenrb@chromium.org, May 26 2017

Mergedinto: 707549
Status: Duplicate (was: Untriaged)
I thought I had reproduced this on trunk but on closer look, I was just hitting a DCHECK (for a debug build). A release build has no crash. It looks like this was fixed last month, but hasn't percolated to Stable yet. Beta channel has the fix already.
Project Member

Comment 5 by sheriffbot@chromium.org, Sep 2 2017

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment