New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 606868 link

Starred by 0 users

Issue metadata

Status: Fixed
Owner: ----
Closed: Dec 2016
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 2
Type: Bug



Sign in to add a comment

Crash in CPDF_RenderStatus::DrawShading

Project Member Reported by ClusterFuzz, Apr 26 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5696428202000384

Fuzzer: tokenfuzz_pdf_april16
Job Type: linux_ubsan_pdfium
Platform Id: linux

Crash Type: UNKNOWN
Crash Address: 
Crash State:
  CPDF_RenderStatus::DrawShading
  CPDF_RenderStatus::ProcessShading
  CPDF_RenderStatus::ProcessObjectNoClip
  

Minimized Testcase (725.47 Kb): https://cluster-fuzz.appspot.com/download/AMIfv95WAGfJeiqBSe9CA6mHe0x20E4bdViwdmuvumOSccx8srtwzaMuGSo4wK5Y5nJMGINsmbKK7-h4lMCuZkjroemdO6Tlr1hntudnCHdpD5HH1i5LHjQH_FkiCIHuo_UU2KH-gVuLevhkGBBnSK2VFnPKpacQCrJdQFKnMxjGos6f6VEe56s

Filer: ivancic

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 
Labels: findit-for-crash Te-Logged M-52 ToolsTestsFindItCorrectResult
Owner: dsinclair@chromium.org
Status: Assigned (was: Available)
Author: Dan Sinclair
Project: chromium-pdfium
Changelist: https://pdfium.googlesource.com/pdfium.git/+/764ec513eecbebd12781bcc96ce81ed5e736ee92
Time: Mon Mar 14 13:35:12 2016 -0400
The CL last changed line 95 of file fpdf_render_pattern.cpp, which is stack frame 0.

@dsinclair: Could you please have a look into this issue.

Thank you.
Cc: dsinclair@chromium.org
Components: Internals>Plugins>PDF
Labels: Needs-Bisect
Owner: rnimmagadda@chromium.org
Labels: -Pri-1 -M-52 -Needs-Bisect Pri-2
Status: Available (was: Assigned)
Looks like a divide by zero error that's always been there.
Cc: rnimmagadda@chromium.org
Owner: ----
Project Member

Comment 5 by ClusterFuzz, Jun 28 2016

ClusterFuzz has detected this testcase as flaky and is unable to reproduce it in the original crash revision. Skipping fixed testing check and marking it as potentially fixed.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5696428202000384

Fuzzer: tokenfuzz_pdf_april16
Job Type: linux_ubsan_pdfium
Platform Id: linux

Crash Type: UNKNOWN
Crash Address: 
Crash State:
  CPDF_RenderStatus::DrawShading
  CPDF_RenderStatus::ProcessShading
  CPDF_RenderStatus::ProcessObjectNoClip
  

Unminimized Testcase: https://cluster-fuzz.appspot.com/download/AMIfv96VB1wyaRP9z6Z2exry746j3yZVb-Wij2fvVPg_aFpR0Ptz_ug6nHYgcwLeZ8up9LqNnjmI3mB9LCw6v4giOg_r2MoRAcnX6CqxLhN9QDlRl8BD6GbrwsJnI6z6Vwz_PcBRUJByxoQlPbbMhIq-JhG2_mPswTbHjfZQaP723dyyMF86AM8?testcase_id=5696428202000384


See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 6 by sheriffbot@chromium.org, Nov 22 2016

Labels: -Restrict-View-EditIssue
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Cc: msrchandra@chromium.org
Status: Fixed (was: Available)
As per Comment# 5, ClusterFuzz has detected the test case as potentially fixed, so changing the status to Fixed.
Please undo if that is not the case.
Thank You.

Sign in to add a comment