Undefined-shift in webrtc::RTCPUtility::RTCPParserV2::ParseTMMBRItem |
||||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=5991820768575488 Fuzzer: libfuzzer_rtcp_receiver_fuzzer Job Type: libfuzzer_chrome_ubsan Platform Id: linux Crash Type: Undefined-shift Crash Address: Crash State: webrtc::RTCPUtility::RTCPParserV2::ParseTMMBRItem IterateTMMBRItem webrtc::RTCPUtility::RTCPParserV2::Iterate Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_ubsan&range=386932:386961 Minimized Testcase (0.04 Kb): https://cluster-fuzz.appspot.com/download/AMIfv97l87wDlR5U1rYEKcPjt0BX3VSnJmudRO4y7e0VbaQUG1Hx-z08HbxRWOzGdLwdu9j0RDvp0AH1nesKFeTC3FL1R_z5rq1H_Wimu1BWamYyVKxm33y7D3YpwZJp-m00cOvRCWcVt-cfhpfqXBnkqy7ABMQ3Ug Additional requirements: Requires Gestures Filer: mmoroz See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Apr 14 2016
,
Apr 14 2016
,
Apr 14 2016
Issue 603484 has been merged into this issue.
,
Apr 19 2016
The following revision refers to this bug: https://chromium.googlesource.com/external/webrtc.git/+/ee6e4272a4cb28ee6cf38bc73585b82f316b0682 commit ee6e4272a4cb28ee6cf38bc73585b82f316b0682 Author: Danil Chapovalov <danilchap@webrtc.org> Date: Tue Apr 19 10:15:10 2016 Fixed undefined shift in parsing Tmmbr, Tmmbn and Remb BUG= chromium:603483 R=asapersson@webrtc.org Review URL: https://codereview.webrtc.org/1888793003 . Cr-Commit-Position: refs/heads/master@{#12423} [modify] https://crrev.com/ee6e4272a4cb28ee6cf38bc73585b82f316b0682/webrtc/modules/rtp_rtcp/source/rtcp_receiver_unittest.cc [modify] https://crrev.com/ee6e4272a4cb28ee6cf38bc73585b82f316b0682/webrtc/modules/rtp_rtcp/source/rtcp_utility.cc
,
Apr 20 2016
ClusterFuzz has detected this issue as fixed in range 388463:388488. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5991820768575488 Fuzzer: libfuzzer_rtcp_receiver_fuzzer Job Type: libfuzzer_chrome_ubsan Platform Id: linux Crash Type: Undefined-shift Crash Address: Crash State: webrtc::RTCPUtility::RTCPParserV2::ParseTMMBRItem IterateTMMBRItem webrtc::RTCPUtility::RTCPParserV2::Iterate Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_ubsan&range=386932:386961 Fixed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_ubsan&range=388463:388488 Minimized Testcase (0.04 Kb): https://cluster-fuzz.appspot.com/download/AMIfv97l87wDlR5U1rYEKcPjt0BX3VSnJmudRO4y7e0VbaQUG1Hx-z08HbxRWOzGdLwdu9j0RDvp0AH1nesKFeTC3FL1R_z5rq1H_Wimu1BWamYyVKxm33y7D3YpwZJp-m00cOvRCWcVt-cfhpfqXBnkqy7ABMQ3Ug Additional requirements: Requires Gestures See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Apr 21 2016
,
Nov 22 2016
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
||||
►
Sign in to add a comment |
||||
Comment 1 by mmoroz@chromium.org
, Apr 14 2016