Crash in CPDF_RenderStatus::DrawShading |
||||||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=5696428202000384 Fuzzer: tokenfuzz_pdf_april16 Job Type: linux_ubsan_pdfium Platform Id: linux Crash Type: UNKNOWN Crash Address: Crash State: CPDF_RenderStatus::DrawShading CPDF_RenderStatus::ProcessShading CPDF_RenderStatus::ProcessObjectNoClip Minimized Testcase (725.47 Kb): https://cluster-fuzz.appspot.com/download/AMIfv95WAGfJeiqBSe9CA6mHe0x20E4bdViwdmuvumOSccx8srtwzaMuGSo4wK5Y5nJMGINsmbKK7-h4lMCuZkjroemdO6Tlr1hntudnCHdpD5HH1i5LHjQH_FkiCIHuo_UU2KH-gVuLevhkGBBnSK2VFnPKpacQCrJdQFKnMxjGos6f6VEe56s Filer: ivancic See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Apr 27 2016
,
Apr 27 2016
Looks like a divide by zero error that's always been there.
,
Apr 29 2016
,
Jun 28 2016
ClusterFuzz has detected this testcase as flaky and is unable to reproduce it in the original crash revision. Skipping fixed testing check and marking it as potentially fixed. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5696428202000384 Fuzzer: tokenfuzz_pdf_april16 Job Type: linux_ubsan_pdfium Platform Id: linux Crash Type: UNKNOWN Crash Address: Crash State: CPDF_RenderStatus::DrawShading CPDF_RenderStatus::ProcessShading CPDF_RenderStatus::ProcessObjectNoClip Unminimized Testcase: https://cluster-fuzz.appspot.com/download/AMIfv96VB1wyaRP9z6Z2exry746j3yZVb-Wij2fvVPg_aFpR0Ptz_ug6nHYgcwLeZ8up9LqNnjmI3mB9LCw6v4giOg_r2MoRAcnX6CqxLhN9QDlRl8BD6GbrwsJnI6z6Vwz_PcBRUJByxoQlPbbMhIq-JhG2_mPswTbHjfZQaP723dyyMF86AM8?testcase_id=5696428202000384 See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Nov 22 2016
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Dec 8 2016
As per Comment# 5, ClusterFuzz has detected the test case as potentially fixed, so changing the status to Fixed. Please undo if that is not the case. Thank You. |
||||||
►
Sign in to add a comment |
||||||
Comment 1 by rnimmagadda@chromium.org
, Apr 27 2016Owner: dsinclair@chromium.org
Status: Assigned (was: Available)