Bugtraq mailing list archives

Google Chrome Browser (ver.0.2.149.27) Vulnerability


From: psy.echo () gmail com
Date: 2 Sep 2008 21:59:47 -0000

---------------------------------------------------
Software:
Google Chrome Browser 0.2.149.27
Tested:
Windows XP Professional SP3
Result:
Google Chrome Crashes with All Tabs
Problem:
An issue exists in how chrome behaves with undefined-handlers in chrome.dll version 0.2.149.27. A crash can result 
without user interaction. When a user is made to visit a malicious link, which has an undefined handler followed by a 
'special' character, the chrome crashes with a Google Chrome message window "Whoa! Google Chrome has crashed. Restart 
now?". It lies in dealing with the POP EBP instruction when pointed out by the EIP register at 0x01002FF4.

Proof of Concept:
http://evilfingers.com/advisory/google_chrome_poc.php
Credit:
Rishi Narang | psy.echo
www.greyhat.in
www.evilfingers.com
---------------------------------------------------


Current thread: