Write beyond bounds in nsDataObjCollection::GetText()
Categories
(Core :: Widget: Win32, enhancement, P3)
Tracking
()
People
(Reporter: q1, Assigned: jstutte)
References
Details
(Keywords: csectype-intoverflow, reporter-external, sec-moderate, Whiteboard: tpi:+, widget-next[adv-main151+][adv-esr140.11+])
Attachments
(2 files, 1 obsolete file)
Updated•9 years ago
|
Updated•9 years ago
|
Comment 3•9 years ago
|
||
Updated•9 years ago
|
Updated•9 years ago
|
Updated•9 years ago
|
Updated•9 years ago
|
Comment 9•8 years ago
|
||
| Reporter | ||
Comment 10•8 years ago
|
||
| Reporter | ||
Comment 11•8 years ago
|
||
Comment 12•8 years ago
|
||
Updated•8 years ago
|
Updated•8 years ago
|
Updated•8 years ago
|
Comment 13•8 years ago
|
||
Updated•7 years ago
|
Updated•7 years ago
|
Updated•7 years ago
|
Updated•7 years ago
|
Updated•3 years ago
|
Updated•2 years ago
|
| Assignee | ||
Comment 14•5 months ago
•
|
||
Re-checked this almost 9 years later: the C++ arithmetic is unchanged, but the
web-reachable exploitation path is most likely closed since 2020.
Vulnerable code is still present. nsDataObjCollection::GetText still
sums uint32_t buffersize + alloclen without overflow checking in both the
CF_TEXT and CF_UNICODETEXT loops, and the same pattern appears in GetFile
and GetFileDescriptors:
https://searchfox.org/firefox-main/rev/ab269cb0e28f247ee5ed83cbc3323c2ba166d508/widget/windows/nsDataObjCollection.cpp#209-294
The class is still wired in via nsDragService::InvokeDragSession for drags
with more than one transferable item, so the code is reachable in principle.
What changed since the original PoC:
-
mozSetDataAt— the API the comment-0 PoC used to populate
mDataObjectswith multi-hundred-MB strings of arbitrary binary content
— is now[ChromeOnly]:
https://searchfox.org/firefox-main/rev/ab269cb0e28f247ee5ed83cbc3323c2ba166d508/dom/webidl/DataTransfer.webidl#114
This was done in bug 1666287, which landed on 2020-09-22 and shipped in
Firefox 83. Web content can no longer reach that path; only chrome JS
can. -
The 2018 PoC (comment 5) required disabling e10s, because with e10s the
IPC pickle release-asserts on integer overflow before the data reaches
the parent (see dveditz, comment 9). e10s is now mandatory, so the
content-driven multi-GB drag aborts safely upstream of this code.
Conclusion: the bug seems no longer exploitable from web content.
It is though still potentially usable as sandbox escape, see bug 2034754.
| Assignee | ||
Comment 15•5 months ago
|
||
Updated•5 months ago
|
Updated•5 months ago
|
| Assignee | ||
Comment 16•5 months ago
|
||
This seems to have been fixed by bug 2034754.
Updated•5 months ago
|
Updated•5 months ago
|
Updated•5 months ago
|
Updated•4 months ago
|
Updated•4 months ago
|
Updated•4 months ago
|
Updated•4 months ago
|
Updated•1 month ago
|
Description
•