New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 603544 link

Starred by 2 users

Issue metadata

Status: Duplicate
Merged: issue 698498
Owner: ----
Closed: Mar 2017
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 1
Type: Bug



Sign in to add a comment

Undefined-shift in opj_j2k_read_siz

Project Member Reported by ClusterFuzz, Apr 14 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6371834743750656

Fuzzer: libfuzzer_pdf_jpx_fuzzer
Job Type: libfuzzer_chrome_ubsan
Platform Id: linux

Crash Type: Undefined-shift
Crash Address: 
Crash State:
  opj_j2k_read_siz
  opj_j2k_read_header_procedure
  opj_j2k_exec
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_ubsan&range=386932:386961

Minimized Testcase (0.14 Kb): https://cluster-fuzz.appspot.com/download/AMIfv95dqmtEle5rd9fjIJCa3NBnQRyLgehXX0rvwDsyDsslFDtJlEv2CjDUSy5aCZh-wT5Yq5OU_sGmMV2j1ACf67Q01H8zwqVEaofCGB6T8s_0sZjv534kqEVK4qvFAADuOTs4918aFZFJzLLQuKlVQzQ098vJVw

Filer: mmoroz

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 

Comment 1 by mmoroz@chromium.org, Apr 14 2016

Cc: och...@chromium.org kcc@chromium.org aizatsky@chromium.org
Components: Internals>Plugins>PDF
Cc: tsepez@chromium.org
Project Member

Comment 3 by ClusterFuzz, Jun 27 2016

ClusterFuzz has detected this testcase as flaky and is unable to reproduce it in the original crash revision. Skipping fixed testing check and marking it as potentially fixed.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6371834743750656

Fuzzer: libfuzzer_pdf_jpx_fuzzer
Job Type: libfuzzer_chrome_ubsan
Platform Id: linux

Crash Type: Undefined-shift
Crash Address: 
Crash State:
  opj_j2k_read_siz
  opj_j2k_read_header_procedure
  opj_j2k_exec
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_ubsan&range=386932:386961

Minimized Testcase (0.14 Kb): https://cluster-fuzz.appspot.com/download/AMIfv96DS_C4bsx-eNdAXyyqqe5zfasIEug-wWctAnsmgZgFAXg8XN2kvNL8oM2lVIfGTgV9nF_jmZgRYUF89uw8aQe_PV0m0xF_ukZ1SP0uz-pqmJCzGeOKudrzQQXbsSFybIH7Jo507QT7WwYFgQdmrHIU83XpcQ?testcase_id=6371834743750656

See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 4 by ClusterFuzz, Jun 29 2016

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5077723009777664

Fuzzer: libfuzzer_pdf_jpx_fuzzer
Job Type: libfuzzer_chrome_ubsan
Platform Id: linux

Crash Type: Undefined-shift
Crash Address: 
Crash State:
  opj_j2k_read_siz
  opj_j2k_read_header_procedure
  opj_j2k_exec
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_ubsan&range=395640:395746

Minimized Testcase (0.14 Kb): https://cluster-fuzz.appspot.com/download/AMIfv96kp93y9uGO5V02e604T1nyWmKSdcxb_hf2AFqRsZ5Sc2pg0VbgAovdGVBSX_n7ua41RHlC2R50ag-cUYukCmTVscmLdQFQFRyf7KBExXH02g_oxcdMrvYio2AUzjBdhm91IpFFiReZkukyNgwvR5kQBy0w6g?testcase_id=5077723009777664

Filer: mmoroz

See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.
Project Member

Comment 5 by sheriffbot@chromium.org, Nov 22 2016

Labels: -Restrict-View-EditIssue
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 6 by ClusterFuzz, Mar 2 2017

Project Member

Comment 7 by ClusterFuzz, Mar 2 2017

Labels: ClusterFuzz-Verified
Status: Verified (was: Available)
ClusterFuzz testcase 5077723009777664 is verified as fixed, so closing issue.

If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
Labels: M-57 ClusterFuzz-Wrong
Status: Available (was: Verified)
This is reported again here  issue 698498  with same regression range as above Comment # 6.Hence re-opening it and marking it available and duping the former into it.
This is impacting to current Stable (56.0.2924.87) & Beta (57.0.2987.88).
Could anyone take a look into this from PDF team.
 Issue 698498  has been merged into this issue.

Comment 10 by npm@chromium.org, Mar 7 2017

Mergedinto: 698498
Status: Duplicate (was: Available)
I'd rather dup into the bug with the unsolved testcase.
Labels: -ClusterFuzz-Wrong
We have made a bunch of changes on ClusterFuzz side, so resetting ClusterFuzz-Wrong label.

Sign in to add a comment