New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 620660 link

Starred by 1 user

Issue metadata

Status: Duplicate
Owner:
Last visit > 30 days ago
Closed: Jun 2016
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 1
Type: Bug-Security



Sign in to add a comment

Memcpy-param-overlap in CCodec_ProgressiveDecoder::GifReadMoreData

Project Member Reported by ClusterFuzz, Jun 16 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5994420365426688

Fuzzer: libfuzzer_pdf_codec_png_fuzzer
Job Type: libfuzzer_chrome_asan
Platform Id: linux

Crash Type: Memcpy-param-overlap
Crash Address: [0x621000012d00,0x621000013ccb) and [0x621000012d35, 0x621000013d00)
Crash State:
  CCodec_ProgressiveDecoder::GifReadMoreData
  CCodec_ProgressiveDecoder::GetFrames
  LLVMFuzzerTestOneInput
  
Recommended Security Severity: Medium

Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_asan&range=398287:398366

Minimized Testcase (4.44 Kb): https://cluster-fuzz.appspot.com/download/AMIfv96J_uUreH3uy7_uJd6oZqrxZL1--1CEdwuUJteZgWeAoNP4HA35zGysL2sqaUWQNvHxeR2AGrPp3Dv15RfH9v-tisAx5pwwcS1NyKj7y2cPRgfs3PotgFGQr_b1Q9a7FmLRUyYoRR3AgrWhXKvu4AACTq3qqA

Filer: mmoroz

See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.
 

Comment 1 by mmoroz@chromium.org, Jun 16 2016

Cc: mmoroz@chromium.org kcc@chromium.org aizatsky@chromium.org
Components: Internals>Plugins>PDF
Looks similar to bug 617092, but this one is still reproducible.
Project Member

Comment 2 by ClusterFuzz, Jun 16 2016

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6056841507504128

Fuzzer: libfuzzer_pdf_codec_tiff_fuzzer
Job Type: libfuzzer_chrome_asan
Platform Id: linux

Crash Type: Memcpy-param-overlap
Crash Address: [0x621000016900,0x6210000178c4) and [0x62100001693c, 0x621000017900)
Crash State:
  CCodec_ProgressiveDecoder::GifReadMoreData
  CCodec_ProgressiveDecoder::GetFrames
  XFACodecFuzzer::Fuzz
  
Recommended Security Severity: Medium

Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_asan&range=398366:399171

Minimized Testcase (4.76 Kb): https://cluster-fuzz.appspot.com/download/AMIfv94r2eSTgiVZgP98wo7MA9nk2uszPF-mNqWmukbKRbxUFsQZg2IUAJ742xrexXtmkEJIZouI85SK1GGrvZ_fUpRvqQ2hhMncI96GnuHfE3QTzaKO_3jaXEVFR71JxtQ5lRmemsYI7z8t2feB9qx1zTcICWxwsQ

Filer: mmoroz

See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.
Project Member

Comment 3 by sheriffbot@chromium.org, Jun 16 2016

Labels: Pri-1

Comment 4 by est...@chromium.org, Jun 16 2016

Cc: och...@chromium.org
Labels: M-53
Owner: hong_zh...@foxitsoftware.com
hong_zhang, can you please take a look?

Comment 5 by est...@chromium.org, Jun 16 2016

Status: Assigned (was: Available)
Project Member

Comment 6 by ClusterFuzz, Jun 16 2016

ClusterFuzz has detected this issue as fixed in range 400121:400191.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6056841507504128

Fuzzer: libfuzzer_pdf_codec_tiff_fuzzer
Job Type: libfuzzer_chrome_asan
Platform Id: linux

Crash Type: Memcpy-param-overlap
Crash Address: [0x621000016900,0x6210000178c4) and [0x62100001693c, 0x621000017900)
Crash State:
  CCodec_ProgressiveDecoder::GifReadMoreData
  CCodec_ProgressiveDecoder::GetFrames
  XFACodecFuzzer::Fuzz
  
Recommended Security Severity: Medium

Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_asan&range=398366:399171
Fixed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_asan&range=400121:400191

Minimized Testcase (4.76 Kb): https://cluster-fuzz.appspot.com/download/AMIfv94r2eSTgiVZgP98wo7MA9nk2uszPF-mNqWmukbKRbxUFsQZg2IUAJ742xrexXtmkEJIZouI85SK1GGrvZ_fUpRvqQ2hhMncI96GnuHfE3QTzaKO_3jaXEVFR71JxtQ5lRmemsYI7z8t2feB9qx1zTcICWxwsQ

See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 7 by sheriffbot@chromium.org, Jun 17 2016

Labels: ReleaseBlock-Beta
This issue is a security regression. If you are not able to fix this quickly, please revert the change that introduced it.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
ochang: Is this actually a beta blocker? Also see  bug 620664  and  bug 620771 .

Comment 9 by och...@chromium.org, Jun 17 2016

Mergedinto: 617092
Status: Duplicate (was: Assigned)
This is a dupe. 
Project Member

Comment 10 by ClusterFuzz, Jul 12 2016

ClusterFuzz has detected this issue as fixed in range 400121:400191.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5994420365426688

Fuzzer: libfuzzer_pdf_codec_png_fuzzer
Job Type: libfuzzer_chrome_asan
Platform Id: linux

Crash Type: Memcpy-param-overlap
Crash Address: [0x621000012d00,0x621000013ccb) and [0x621000012d35, 0x621000013d00)
Crash State:
  CCodec_ProgressiveDecoder::GifReadMoreData
  CCodec_ProgressiveDecoder::GetFrames
  LLVMFuzzerTestOneInput
  
Recommended Security Severity: Medium

Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_asan&range=398287:398366
Fixed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_asan&range=400121:400191

Minimized Testcase (4.44 Kb): https://cluster-fuzz.appspot.com/download/AMIfv96J_uUreH3uy7_uJd6oZqrxZL1--1CEdwuUJteZgWeAoNP4HA35zGysL2sqaUWQNvHxeR2AGrPp3Dv15RfH9v-tisAx5pwwcS1NyKj7y2cPRgfs3PotgFGQr_b1Q9a7FmLRUyYoRR3AgrWhXKvu4AACTq3qqA?testcase_id=5994420365426688

See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 11 by sheriffbot@chromium.org, Sep 25 2016

Labels: -Restrict-View-SecurityTeam
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 12 by sheriffbot@chromium.org, Oct 1 2016

This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 13 by sheriffbot@chromium.org, Oct 2 2016

This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Labels: allpublic

Sign in to add a comment