Closed
Bug 1191489
Opened 9 years ago
Closed 6 years ago
AddressSanitizer: attempting free on address which was not malloc()-ed with Flash 11.2.202.491
Categories
(External Software Affecting Firefox Graveyard :: Flash (Adobe), defect)
External Software Affecting Firefox Graveyard
Flash (Adobe)
x86_64
Linux
Tracking
(Not tracked)
RESOLVED
WORKSFORME
People
(Reporter: bc, Unassigned)
Details
(Keywords: sec-vector, Whiteboard: [asan])
Attachments
(3 files)
1. http://entitlement.auth.adobe.com/entitlement/AccessEnabler.swf with ASAN enabled Beta/40, Aurora/41, Nightly/42 on Linux x86_64 Flash 11.2.202.491
2. ==12653==ERROR: AddressSanitizer: attempting free on address which was not malloc()-ed: 0x0000020fb030 in thread T0
Get build from http://ftp.mozilla.org/pub/mozilla.org/firefox/tinderbox-builds/mozilla-central-linux64-asan/latest/
Reporter | ||
Comment 1•9 years ago
|
||
Reporter | ||
Updated•9 years ago
|
Attachment #8643904 -
Attachment mime type: text/x-log → text/plain
Comment 2•9 years ago
|
||
Aaron, should we report this to Adobe or something? Can you do that? Thanks.
Flags: needinfo?(aklotz)
Keywords: sec-vector
Reporter | ||
Comment 3•9 years ago
|
||
A number of crashes which were reproducible prior to the Flash update this week were fixed. Let me retest this using a new asan build with the latest flash update.
Comment 4•9 years ago
|
||
Setting ni? on bc until we know whether this has already been fixed.
Flags: needinfo?(aklotz) → needinfo?(bob)
Reporter | ||
Comment 5•9 years ago
|
||
This is still reproducible with today's opt asan build on Linux x86_64 with Flash 11.2.202.508 by loading http://entitlement.auth.adobe.com/entitlement/AccessEnabler.swf
This brings up the additional point on how to handle Flash crashes in Bughunter automation in general. I normally see several medium/high exploitability rated crashes with the occasional EXCEPTION_ACCESS_VIOLATION_EXEC reason. How do we want to handle these in the future?
Flags: needinfo?(bob)
Comment 6•9 years ago
|
||
Jeromie, can you have somebody look into this, please?
Flags: needinfo?(jeclark)
Updated•9 years ago
|
Group: core-security → core-security-release
Comment 8•9 years ago
|
||
We were not able to get this to reproduce on our end, but we added a blind fix in Flash Player 11.2.r202.518 or higher that we believe should resolve it. It would be great if you guys could confirm.
Comment 9•9 years ago
|
||
* Sorry, I copied this from the bug comment, but I just noticed that the version indicated is a typo, and is supposed to be 11.2.202.218
Reporter | ||
Comment 10•9 years ago
|
||
I can reproduce with the original swf and the current one on Fedora 22 with today's opt asan 64 bit build with Flash 11.2.202.508-release.
Comment 11•9 years ago
|
||
I'll send you a drop of 11.2.202.530
Reporter | ||
Comment 12•9 years ago
|
||
Sorry for the delay but I have been experiencing issues with display on Fedora.
With Flash 11.2.202.530 x86_64 with xorg-x11-drv-nouveau.x86_64 1:1.0.11-2.fc22 I can reproduce:
ERROR: AddressSanitizer: attempting free on address which was not malloc()-ed
When I boot with ACPI=off and access the machine via VNC I can not reproduce this.
Reporter | ||
Comment 13•9 years ago
|
||
The previous comment was on Fedora 22 with Kernel 4.1.6. I also tried this on an ESXi VM RHEL6 2.6.32-573.3.1 and could not reproduce.
Tomcat: do you have a Linux system (not a vm and not over vnc) that you could test this with?
jeclark: do you mind if I pass the 11.2.202.530 to Tomcat?
Flags: needinfo?(jeclark)
Flags: needinfo?(cbook)
Comment 14•9 years ago
|
||
(In reply to Bob Clary [:bc:] from comment #13)
> The previous comment was on Fedora 22 with Kernel 4.1.6. I also tried this
> on an ESXi VM RHEL6 2.6.32-573.3.1 and could not reproduce.
>
> Tomcat: do you have a Linux system (not a vm and not over vnc) that you
> could test this with?
>
> jeclark: do you mind if I pass the 11.2.202.530 to Tomcat?
Hey Bob, i don't have a physical maschine with linux anymore, all are mac's etc with vms for linux. so i guess i can't help here. sorry!
Flags: needinfo?(cbook)
Comment 15•9 years ago
|
||
@bclary: You're welcome to share those internally.
Flags: needinfo?(jeclark)
Comment 16•9 years ago
|
||
Version and milestone values are being reset to defaults as part of product refactoring.
Version: 11.x → unspecified
Comment 17•6 years ago
|
||
rahib@adobe.com has requested to be cc'ed on this bug.
Flags: needinfo?(jeclark)
Flags: needinfo?(dveditz)
Updated•6 years ago
|
Flags: needinfo?(dveditz)
Comment 18•6 years ago
|
||
Qusta Rahib works for me. He's welcome to have visibility on this bug.
In terms of the status of the bug itself:
We stopped shipping the Flash Player 11.2 branch a couple years ago. We had been maintaining a branch of Flash Player 11.2 with security patches for a few year as a result of a a decision to freeze NPAPI on Linux and carry PPAPI forward as the supported path. This was primarily a product of the introduction of hardware graphics acceleration in Flash and the fact that PPAPI offered much better abstraction to the graphics implementations across Linux distributions.
We ultimately began shipping an NPAPI Flash Player again from current branches (with some features disabled) as the accumulated bit-rot and build system dependencies on old infrastructure made it incredibly difficult to maintain.
So... this bug is probably moot, as this branch no longer ships and hasn't in a long time. If you're seeing exploitable crashes in current Flash Player versions, those are definitely things that we want to know about and fix. Please feel free to copy me on new bugs, and it would be great if you could forward them to the Adobe Product Security Incident Response Team (PSIRT) at psirt@adobe.com. That account is staffed 24/7/365 and they're positioned to rally resources and follow up so that there's no single human point of failure.
Thanks!
Flags: needinfo?(jeclark)
Comment 19•6 years ago
|
||
Is this issue still occurring in the latest Firefox & Flash? If so, please provide steps to reproduce.
I've installed Fedora 28 and downloaded the the latest FireFox Nightly Asan from here. https://archive.mozilla.org/pub/firefox/nightly/latest-mozilla-central/firefox-64.0a1.en-US.linux-x86_64-asan-reporter.tar.bz2
I Tested AccessEnabled.swf with current release 31.0.0.122 & latest builds 32.0.0.58 and had no luck reproducing the issue.
Flags: needinfo?(bob)
Reporter | ||
Comment 20•6 years ago
|
||
I would go ahead and mark it works for me if you can't reproduce with a fresh Firefox build and Flash build. I no longer allow Flash on my machines.
Flags: needinfo?(bob)
Comment 21•6 years ago
|
||
(In reply to Bob Clary [:bc:] from comment #20)
> I would go ahead and mark it works for me if you can't reproduce with a
> fresh Firefox build and Flash build. I no longer allow Flash on my machines.
I don't see where to mark it "works" is there an option for that?
Thanks
Flags: needinfo?(bob)
Reporter | ||
Comment 22•6 years ago
|
||
The Bugzilla UI changes are a little tricky. Select FIXED then you can change it to WORKSFORME. Done.
Status: NEW → RESOLVED
Closed: 6 years ago
Flags: needinfo?(bob)
Resolution: --- → WORKSFORME
Updated•5 years ago
|
Group: core-security-release
Updated•2 years ago
|
Product: External Software Affecting Firefox → External Software Affecting Firefox Graveyard
You need to log in
before you can comment on or make changes to this bug.
Description
•