Crash in CPDF_Array::GetDirectObjectAt |
|||||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=6521327267086336 Fuzzer: tokenfuzz_pdf_march16 Job Type: linux_asan_pdfium Platform Id: linux Crash Type: UNKNOWN READ Crash Address: 0x000000000018 Crash State: CPDF_Array::GetDirectObjectAt CPDF_DataAvail::CheckHintTables CPDF_DataAvail::CheckDocStatus Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_pdfium&range=357360:357514 Minimized Testcase (1171.47 Kb): https://cluster-fuzz.appspot.com/download/AMIfv94oLhst185djeNF-QCsecmCAEPs6hLsuc-fw2Wy7VPskx48VmejQfY_Ar509p3ulI2DQMcIELocWR_Gz30aKg-j8lB-f4Cdu08_nmIRz8jwmU3BEwxl-55xL5JoT8gsnhaPBXVh6r3PPzE4DVVy0zsH9qmV5Yqt2FkmDzre5goxyzAnAE0 Filer: ivancic See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Apr 6 2016
Jun no longer involved with this project.
,
May 18 2016
,
May 18 2016
Probably the "H" key exists but it's not an array. Probably need to change the KeyExist() checks to make sure the keys are the expected types.
,
May 19 2016
Possibly related: bug 613031 , bug 610555 , and bug 591088.
,
Jun 8 2016
ClusterFuzz has detected this issue as fixed in range 398351:398496. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6521327267086336 Fuzzer: tokenfuzz_pdf_march16 Job Type: linux_asan_pdfium Platform Id: linux Crash Type: UNKNOWN READ Crash Address: 0x000000000018 Crash State: CPDF_Array::GetDirectObjectAt CPDF_DataAvail::CheckHintTables CPDF_DataAvail::CheckDocStatus Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_pdfium&range=357360:357514 Fixed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_pdfium&range=398351:398496 Minimized Testcase (1171.47 Kb): https://cluster-fuzz.appspot.com/download/AMIfv95Dq2KGud7mEifQx1uemOFT0-Z5Nl26luwr4HFh9Tx9ltQchDYbPGdt_yflUYe05s1sc8dR7KnuCz_WIkxmQR_uivYXM5pQIgt5fHUEhKmNtntjxsOf--yzMZYSW-3kBENLaHKPZGSdctKxtuB9jkuPYTsC-Gpwc3X6Ls0KCHX8-dA4W20 See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Jun 14 2016
ClusterFuzz testcase is verified as fixed, closing issue. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
,
Jun 23 2016
,
Jul 8 2016
Issue 626718 has been merged into this issue.
,
Nov 22 2016
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
|||||
►
Sign in to add a comment |
|||||
Comment 1 by ashej...@chromium.org
, Apr 6 2016Owner: jun_f...@foxitsoftware.com
Status: Assigned (was: Available)