Issue metadata
Sign in to add a comment
|
Crash in v8::internal::MaybeHandle<v8::internal::Object> v8::internal::HandleApiCallHelpe |
||||||||||||||||||||||||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=5293918089904128 Fuzzer: inferno_twister Job Type: linux_asan_chrome_media Platform Id: linux Crash Type: UNKNOWN READ Crash Address: 0x00017fff7fff Crash State: v8::internal::MaybeHandle<v8::internal::Object> v8::internal::HandleApiCallHelpe v8::internal::Builtins::InvokeApiFunction v8::internal::Object::GetPropertyWithAccessor Recommended Security Severity: Medium Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_media&range=375259:376263 Minimized Testcase (3.14 Kb): https://cluster-fuzz.appspot.com/download/AMIfv94jYVEBklnwcf6yWSehsSz_m6Gldh6qSncAPlcKrLousQltdS-E0lbaTkME2CxE9-odRL8kn5vbosyEhVhEzEAuLVBi-MlqKGgvdIJFxN48CFfflFmqbvOBLEfL1mlg4sjcMCz2E86Y5YiDxhXS-pEVigUWMQ Filer: inferno See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Mar 31 2016
,
Apr 4 2016
,
Apr 7 2016
ClusterFuzz has detected this issue as fixed in range 385386:385441. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5293918089904128 Fuzzer: inferno_twister Job Type: linux_asan_chrome_media Platform Id: linux Crash Type: UNKNOWN READ Crash Address: 0x00017fff7fff Crash State: v8::internal::MaybeHandle<v8::internal::Object> v8::internal::HandleApiCallHelpe v8::internal::Builtins::InvokeApiFunction v8::internal::Object::GetPropertyWithAccessor Recommended Security Severity: Medium Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_media&range=375259:376263 Fixed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_media&range=385386:385441 Minimized Testcase (3.14 Kb): https://cluster-fuzz.appspot.com/download/AMIfv94jYVEBklnwcf6yWSehsSz_m6Gldh6qSncAPlcKrLousQltdS-E0lbaTkME2CxE9-odRL8kn5vbosyEhVhEzEAuLVBi-MlqKGgvdIJFxN48CFfflFmqbvOBLEfL1mlg4sjcMCz2E86Y5YiDxhXS-pEVigUWMQ See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Apr 14 2016
,
Apr 21 2016
mstarzinger: Uh oh! This issue still open and hasn't been updated in the last 20 days. This is a serious vulnerability, and we want to ensure that there's progress. Could you please leave an update with the current status and any potential blockers? If you're not the right owner for this issue, could you please remove yourself as soon as possible or help us find the right one? If the issue is fixed or you can't reproduce it, please close the bug. If you've started working on a fix, please set the status to Started. Thanks for your time! To disable nags, add the Disable-Nags label. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Apr 21 2016
,
Jul 29 2016
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Oct 1 2016
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Oct 2 2016
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Oct 2 2016
|
|||||||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||||||
Comment 1 by infe...@chromium.org
, Mar 31 2016Owner: mstarzinger@chromium.org
Status: Assigned (was: Available)