New issue
Advanced search Search tips

Issue 600941 link

Starred by 0 users

Issue metadata

Status: WontFix
Owner:
Closed: Apr 2016
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 2
Type: Bug-Regression



Sign in to add a comment

Crash in CXFA_FMAssignExpression::ToJavaScript

Project Member Reported by ClusterFuzz, Apr 6 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6125328138764288

Fuzzer: libfuzzer_pdf_fm2js_fuzzer
Job Type: libfuzzer_chrome_asan
Platform Id: linux

Crash Type: UNKNOWN
Crash Address: 0x000000000000
Crash State:
  CXFA_FMAssignExpression::ToJavaScript
  CXFA_FMExpExpression::ToJavaScript
  CXFA_FMFunctionDefinition::ToJavaScript
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_asan&range=375725:375769

Minimized Testcase (0.06 Kb):
Download: https://cluster-fuzz.appspot.com/download/AMIfv957yAVDCkY_9XKmWes7TLXBRMC2OFVF-16o_Yo916g3FCfHi-Mb6e_lBGwOKGIBL39QqE5FHNTdkx00Kpq3OLWYXuL7szWOcUY1NPuekm_ShwA_TdPkjiGdNnXNYMRs_SR7xH11Hj2Ly7t2JcJOQ9lBeEINkA
c=if(fh)=;>=5oc.8a.creturnifunf(ivee:	*!
()c�<c!n!-'o=n'n"c�o


Filer: msrchandra

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 
Labels: -Pri-1 -Type-Bug findit-wrong Te-Logged Pri-2 Type-Bug-Regression
Owner: och...@chromium.org
Status: Assigned (was: Available)
Providing the CL --
https://chromium.googlesource.com/chromium/src/+log/0b3f35792348a350345b0b2d2ca33e8c51211b03..eb96710a11766d60a321033bbf1222bab3fa3fc5?pretty=fuller

Not possible suspect has been identified from find it --
Suspected CLs	Findit could not find any suspected CLs.

Suspected Component: chromium

Could not even find the suspect from CL and Code Search also.
Assigning to a concern Dev who worked on the same bug previously,

@ochang -- Could you please look into the issue and update, pardon me if it has nothing to do with your changes and if possible please assign it to the concern Dev.
Thank You.
Project Member

Comment 2 by ClusterFuzz, Apr 6 2016

ClusterFuzz has detected this issue as fixed in range 379054:379821.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6125328138764288

Fuzzer: libfuzzer_pdf_fm2js_fuzzer
Job Type: libfuzzer_chrome_asan
Platform Id: linux

Crash Type: UNKNOWN
Crash Address: 0x000000000000
Crash State:
  CXFA_FMAssignExpression::ToJavaScript
  CXFA_FMExpExpression::ToJavaScript
  CXFA_FMFunctionDefinition::ToJavaScript
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_asan&range=375725:375769
Fixed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_asan&range=379054:379821

Minimized Testcase (0.06 Kb):
Download: https://cluster-fuzz.appspot.com/download/AMIfv957yAVDCkY_9XKmWes7TLXBRMC2OFVF-16o_Yo916g3FCfHi-Mb6e_lBGwOKGIBL39QqE5FHNTdkx00Kpq3OLWYXuL7szWOcUY1NPuekm_ShwA_TdPkjiGdNnXNYMRs_SR7xH11Hj2Ly7t2JcJOQ9lBeEINkA
c=if(fh)=;>=5oc.8a.creturnifunf(ivee:	*!
()c�<c!n!-'o=n'n"c�o


See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Status: WontFix (was: Assigned)
This is already fixed.
Project Member

Comment 4 by sheriffbot@chromium.org, Nov 22 2016

Labels: -Restrict-View-EditIssue
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment