New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 603911 link

Starred by 0 users

Issue metadata

Status: WontFix
Owner:
Closed: Apr 2016
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 1
Type: Bug-Security



Sign in to add a comment

Heap-buffer-overflow in void v8::internal::String::WriteToFlat<unsigned short>

Project Member Reported by ClusterFuzz, Apr 15 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=4941403133575168

Fuzzer: inferno_webbot
Job Type: linux_asan_chrome_chromeos
Platform Id: linux

Crash Type: Heap-buffer-overflow READ 8
Crash Address: 0x62f000061824
Crash State:
  void v8::internal::String::WriteToFlat<unsigned short>
  v8::internal::GenericStringUtf16CharacterStream::FillBuffer
  v8::internal::BufferedUtf16CharacterStream::ReadBlock
  
Recommended Security Severity: Medium

Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_chromeos&range=387207:387248

Unminimized Testcase: https://cluster-fuzz.appspot.com/download/AMIfv96UXqQG9Fsx4qBhcExBL_PsLlxZvnGVwR2yK3zD5d98u5O4LXYXZtEsS1SO0VnUTCoUAIst0_b8D24HIJWtIh970erXh4dTlu1gQRtxEjvdT9dm2v_v7qH_s1sJPCDuJ5mY9hjclXWyeqjXmrbDYV5xh0TSEQ


Filer: mmoroz

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 

Comment 1 by mmoroz@chromium.org, Apr 15 2016

Cc: kcc@chromium.org aizatsky@chromium.org
Owner: jochen@chromium.org
I think that I should assign it to marja@, but she is OOO. jochen@ please help to find an owner :)
Project Member

Comment 2 by ClusterFuzz, Apr 15 2016

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5765549912489984

Fuzzer: meacer_chromebot_extensions
Job Type: windows_asan_chrome
Platform Id: windows

Crash Type: Heap-buffer-overflow READ 8
Crash Address: 0x50c0d824
Crash State:
  v8::internal::String::WriteToFlat
  v8::internal::GenericStringUtf16CharacterStream::FillBuffer
  v8::internal::BufferedUtf16CharacterStream::ReadBlock
  
Recommended Security Severity: Medium

Regressed: https://cluster-fuzz.appspot.com/revisions?job=windows_asan_chrome&range=387207:387261

Minimized Testcase (121.77 Kb): https://cluster-fuzz.appspot.com/download/AMIfv94r1tsscVoqkLXjl79-o7hs0ASgpVoMUhNOUOeUmWYSOh9Xc4jdoMujCeBKajExBtTTu4C-td8S8Rv-L_25rQTSBVHlt0dfe45N0eNip7mGIjSr1oji9J1VxCrDB1DUoQGJOa7m7ikvFpY-mkxvs8bRiaq8RDc1LiY34uuV12PiPM_8Zgw

Filer: mmoroz

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

Comment 3 by jochen@chromium.org, Apr 15 2016

Cc: jochen@chromium.org
Owner: vogelheim@chromium.org
Project Member

Comment 4 by ClusterFuzz, Apr 15 2016

ClusterFuzz has detected this testcase as flaky and is unable to reproduce it in the original crash revision. Skipping fixed testing check and marking it as potentially fixed.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5765549912489984

Fuzzer: meacer_chromebot_extensions
Job Type: windows_asan_chrome
Platform Id: windows

Crash Type: Heap-buffer-overflow READ 8
Crash Address: 0x50c0d824
Crash State:
  v8::internal::String::WriteToFlat
  v8::internal::GenericStringUtf16CharacterStream::FillBuffer
  v8::internal::BufferedUtf16CharacterStream::ReadBlock
  
Recommended Security Severity: Medium

Regressed: https://cluster-fuzz.appspot.com/revisions?job=windows_asan_chrome&range=387207:387261

Minimized Testcase (121.77 Kb): https://cluster-fuzz.appspot.com/download/AMIfv94r1tsscVoqkLXjl79-o7hs0ASgpVoMUhNOUOeUmWYSOh9Xc4jdoMujCeBKajExBtTTu4C-td8S8Rv-L_25rQTSBVHlt0dfe45N0eNip7mGIjSr1oji9J1VxCrDB1DUoQGJOa7m7ikvFpY-mkxvs8bRiaq8RDc1LiY34uuV12PiPM_8Zgw

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.

Comment 5 by tsepez@chromium.org, Apr 15 2016

Components: Blink>JavaScript
Labels: M-50 Pri-2
Project Member

Comment 6 by ClusterFuzz, Apr 15 2016

ClusterFuzz has detected this issue as fixed in range 387322:387345.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=4941403133575168

Fuzzer: inferno_webbot
Job Type: linux_asan_chrome_chromeos
Platform Id: linux

Crash Type: Heap-buffer-overflow READ 8
Crash Address: 0x62f000061824
Crash State:
  void v8::internal::String::WriteToFlat<unsigned short>
  v8::internal::GenericStringUtf16CharacterStream::FillBuffer
  v8::internal::BufferedUtf16CharacterStream::ReadBlock
  
Recommended Security Severity: Medium

Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_chromeos&range=387207:387248
Fixed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_chromeos&range=387322:387345

Unminimized Testcase: https://cluster-fuzz.appspot.com/download/AMIfv96UXqQG9Fsx4qBhcExBL_PsLlxZvnGVwR2yK3zD5d98u5O4LXYXZtEsS1SO0VnUTCoUAIst0_b8D24HIJWtIh970erXh4dTlu1gQRtxEjvdT9dm2v_v7qH_s1sJPCDuJ5mY9hjclXWyeqjXmrbDYV5xh0TSEQ


See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 7 by ClusterFuzz, Apr 15 2016

Labels: -Pri-2 Pri-1
Status: Assigned (was: Available)
Project Member

Comment 8 by sheriffbot@chromium.org, Apr 16 2016

Labels: -Security_Impact-Head Security_Impact-Stable
Status: WontFix (was: Assigned)
Can't reproduce at tip of tree. ClusterFuzz can't repro either. -> Closing.
Project Member

Comment 10 by sheriffbot@chromium.org, Jul 28 2016

Labels: -Restrict-View-SecurityTeam
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 11 by sheriffbot@chromium.org, Oct 1 2016

This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 12 by sheriffbot@chromium.org, Oct 2 2016

This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Labels: allpublic

Sign in to add a comment