New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 804636 link

Starred by 1 user

Issue metadata

Status: Fixed
Owner:
Last visit > 30 days ago
Closed: Mar 2018
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux , Windows , Chrome , Mac
Pri: 1
Type: Bug-Security



Sign in to add a comment

Security: Adobe Flash AdBannerAsset Object Type Confusion

Reported by xiong12...@gmail.com, Jan 23 2018

Issue description


VULNERABILITY DETAILS

This is a type confusion vulnerability. This vulnerability is caused by an Exception thrown in a middle of a parent class’s constructor function. 


VERSION
Chrome Version: Version 64.0.3282.100 (Official Build) beta (64-bit)
Operating System: Winows 7 64-bits

REPRODUCTION CASE

Visit poc.swf with chrome to observe the crash.


FOR CRASHES, PLEASE INCLUDE THE FOLLOWING ADDITIONAL INFORMATION

Type of crash: tab


0:017> g
(6e8.4cc): Access violation - code c0000005 (first chance)
First chance exceptions are reported before any exception handling.
This exception may be expected and handled.
*** ERROR: Symbol file could not be found.  Defaulted to export symbols for C:\Users\yuki\AppData\Local\Google\Chrome\User Data\PepperFlash\28.0.0.137\pepflashplayer.dll - 
pepflashplayer!PPP_ShutdownBroker+0xb2920:
000007fe`d26f6c30 440fb609        movzx   r9d,byte ptr [rcx] ds:00000000`0016c000=??
0:000> k
Child-SP          RetAddr           Call Site
00000000`003bd818 000007fe`d26f8131 pepflashplayer!PPP_ShutdownBroker+0xb2920
00000000`003bd820 000007fe`d26f4517 pepflashplayer!PPP_ShutdownBroker+0xb3e21
00000000`003bd8a0 00000355`389b8fac pepflashplayer!PPP_ShutdownBroker+0xb0207
00000000`003bd8e0 00000000`00000000 0x355`389b8fac
 
Please credit "Yuki Chen of Qihoo 360 Vulcan Team" for this bug, thank you!
Components: Internals>Plugins>Flash
Owner: natashenka@google.com
Thanks, I've reported this to Adobe
Status: ExternalDependency (was: Unconfirmed)
This is PSIRT-7808
Labels: Security_Severity-High Security_Impact-Stable
Project Member

Comment 7 by sheriffbot@chromium.org, Feb 15 2018

Labels: M-64
Project Member

Comment 8 by sheriffbot@chromium.org, Feb 15 2018

Labels: Pri-1
Project Member

Comment 9 by sheriffbot@chromium.org, Mar 7 2018

Labels: -M-64 M-65
Labels: OS-Chrome OS-Linux OS-Mac OS-Windows
Status: Fixed (was: ExternalDependency)
This was resolved today as CVE-2018-4920
Labels: reward-topanel CVE-2018-4920
Project Member

Comment 13 by sheriffbot@chromium.org, Mar 14 2018

Labels: -Restrict-View-SecurityTeam Restrict-View-SecurityNotify
Project Member

Comment 14 by sheriffbot@chromium.org, Mar 16 2018

Labels: Merge-Request-66
Project Member

Comment 15 by sheriffbot@chromium.org, Mar 16 2018

Labels: -Merge-Request-66 Merge-Review-66 Hotlist-Merge-Review
This bug requires manual review: M66 has already been promoted to the beta branch, so this requires manual review
Please contact the milestone owner if you have questions.
Owners: cmasso@(Android), cmasso@(iOS), josafat@(ChromeOS), abdulsyed@(Desktop)

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
What's the fix that needs to be merged to M66?
Labels: -reward-topanel reward-unpaid reward-3000
*** Boilerplate reminders! ***
Please do NOT publicly disclose details until a fix has been released to all our users. Early public disclosure may cancel the provisional reward. Also, please be considerate about disclosure when the bug affects a core library that may be used by other products. Please do NOT share this information with third parties who are not directly involved in fixing the bug. Doing so may cancel the provisional reward. Please be honest if you have already disclosed anything publicly or to third parties. Lastly, we understand that some of you are not interested in money. We offer the option to donate your reward to an eligible charity. If you prefer this option, let us know and we will also match your donation - subject to our discretion. Any rewards that are unclaimed after 12 months will be donated to a charity of our choosing.
*********************************
The VRP panel decided to award $3,000 for this report, thanks!
Cc: awhalley@chromium.org
btw xiong12002@, how would you like to be credited if this is included in Chrome release notes?
Labels: -reward-unpaid reward-inprocess
Labels: -Merge-Review-66
no merge needed. 
Labels: CVE_description-missing
Project Member

Comment 23 by sheriffbot@chromium.org, Jun 20 2018

Labels: -Restrict-View-SecurityNotify allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Labels: -CVE_description-missing CVE_description-submitted

Sign in to add a comment