New issue
Advanced search Search tips
Starred by 1 user
Status: Invalid
Owner:
Closed: Sep 11
Cc:



Sign in to add a comment
Invalid: GDATA AV crashes on malicious RAR files from 2013
Project Member Reported by thomasdullien@google.com, Jun 6 Back to list
Please see https://bugs.chromium.org/p/project-zero/issues/detail?id=1278&desc=2
for further details.

This bug is subject to a 90 day disclosure deadline. After 90 days elapse
or a patch has been made broadly available, the bug report will become
visible to the public.

 
Project Member Comment 1 by thomasdullien@google.com, Jun 9
See https://bugs.chromium.org/p/project-zero/issues/detail?id=1286 - turns out VMSF_DELTA is still broken in upstream RAR.
Project Member Comment 2 by thomasdullien@google.com, Jun 9
Description: Show this description
Project Member Comment 3 by thomasdullien@google.com, Sep 11
Labels: -Restrict-View-Commit
As shown in the June 9th comment, the crash was not GDATA's fault, but rather unfixed bug in unrar upstream. Derestricting.
Project Member Comment 4 by thomasdullien@google.com, Sep 11
Status: Invalid
Project Member Comment 5 by thomasdullien@google.com, Sep 11
Summary: Invalid: GDATA AV crashes on malicious RAR files from 2013 (was: GDATA AV crashes on malicious RAR files from 2013)
Sign in to add a comment