Issue metadata
Sign in to add a comment
|
Heap-buffer-overflow in FPDFAPI_inflate |
||||||||||||||||||||||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=6467474099011584 Fuzzer: attekett_dom_fuzzer Job Type: linux_lsan_chrome_mp Platform Id: linux Crash Type: Heap-buffer-overflow WRITE 9 Crash Address: 0x6020000088f4 Crash State: FPDFAPI_inflate PixarLogDecode TIFFReadEncodedTile Recommended Security Severity: High Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_lsan_chrome_mp&range=393856:393893 Minimized Testcase (3.86 Kb): https://cluster-fuzz.appspot.com/download/AMIfv96FAOwQcJuvFrct2eUWkbXWaiCMAYXUo0XlpS9EBts0Se9SE89pzLKeQ-2zJrS2ULk5aKLaYbPEcOoVShPMmyrFOtGl9HUUPMcStDP3eZ5eI_ImZflt-E03KtBl1v_6WIgSVBbm_fHI9p50Q8X9FypQEnX5aw?testcase_id=6467474099011584 Filer: aarya See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Jun 29 2016
If it's TIFF, then it's XFA, and we don't have XFA turned on, yet. Punting to ochang for triaging.
,
Jun 29 2016
Punting to foxit. The CF report has a really old crashing revision (from before XFA got turned off on HEAD).
,
Jun 30 2016
ClusterFuzz has detected this issue as fixed in range 398351:398496. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6467474099011584 Fuzzer: attekett_dom_fuzzer Job Type: linux_lsan_chrome_mp Platform Id: linux Crash Type: Heap-buffer-overflow WRITE 9 Crash Address: 0x6020000088f4 Crash State: FPDFAPI_inflate PixarLogDecode TIFFReadEncodedTile Recommended Security Severity: High Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_lsan_chrome_mp&range=393856:393893 Fixed: https://cluster-fuzz.appspot.com/revisions?job=linux_lsan_chrome_mp&range=398351:398496 Minimized Testcase (3.86 Kb): https://cluster-fuzz.appspot.com/download/AMIfv96FAOwQcJuvFrct2eUWkbXWaiCMAYXUo0XlpS9EBts0Se9SE89pzLKeQ-2zJrS2ULk5aKLaYbPEcOoVShPMmyrFOtGl9HUUPMcStDP3eZ5eI_ImZflt-E03KtBl1v_6WIgSVBbm_fHI9p50Q8X9FypQEnX5aw?testcase_id=6467474099011584 See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Jun 30 2016
ClusterFuzz testcase is verified as fixed, closing issue. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
,
Jun 30 2016
,
Jun 30 2016
,
Sep 28 2016
removing reward-topanel for Security_Impact-None bugs
,
Oct 8 2016
,
Oct 8 2016
,
Oct 2 2017
Looks like an XFA issue, we should verify if it's fixed or not.
,
Oct 3 2017
Confirmed fixed on HEAD
,
Jan 9 2018
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
|||||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||||
Comment 1 by palmer@chromium.org
, Jun 29 2016Components: Internals>Plugins>PDF
Labels: M-53 OS-Android OS-Chrome OS-Mac OS-Windows
Owner: thestig@chromium.org
Status: Assigned (was: Available)