Integer-overflow in dmg_fp::strtod |
|||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=6351706208337920 Fuzzer: libfuzzer_base_json_reader_fuzzer Job Type: libfuzzer_chrome_ubsan Platform Id: linux Crash Type: Integer-overflow Crash Address: Crash State: dmg_fp::strtod base::StringToDouble base::internal::JSONParser::ConsumeNumber Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_ubsan&range=395640:395746 Minimized Testcase (0.01 Kb): Download: https://cluster-fuzz.appspot.com/download/AMIfv97JnS77FRiL82iSJeHxjlFKDRuMan_I8fEb1UZ3Fi55XaW2jt_Qim9IWrjBiScosI25FNlz47aw8N0lj1sQNGfVKDfAFPJl26sa06SPYb506dvAU4WoYuAd2RB_5IRlZIzTiZq-IziztnYq1XNg6StcLjpgbQ?testcase_id=6351706208337920 9e5290015000 Filer: brajkumar See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.
,
Jul 29 2016
Detailed report: https://cluster-fuzz.appspot.com/testcase?key=4514552998002688 Fuzzer: libfuzzer_base_json_reader_fuzzer Job Type: libfuzzer_chrome_ubsan Platform Id: linux Crash Type: Integer-overflow Crash Address: Crash State: dmg_fp::strtod base::StringToDouble base::internal::JSONParser::ConsumeNumber Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_ubsan&range=395640:395746 Minimized Testcase (0.01 Kb): Download: https://cluster-fuzz.appspot.com/download/AMIfv97iqaElfgzEOXGJomjvCDOOwRbLxGNEVWPyFA_I_dTlfWwQYB4tBXtkwex_LIvvr0mY5lgbqLjHYEs-VlSstdzYplNu9R-Zpgrn7jEkfGnFhOJz-5XpZ6Gf7ac1Csa6bWo-I0tueXfb4Sl48OnUrZ6j021vVg?testcase_id=4514552998002688 9e5290015000 Filer: rnimmagadda See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.
,
Aug 25 2016
ClusterFuzz has detected this issue as fixed in range 413961:414068. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=4514552998002688 Fuzzer: libfuzzer_base_json_reader_fuzzer Job Type: libfuzzer_chrome_ubsan Platform Id: linux Crash Type: Integer-overflow Crash Address: Crash State: dmg_fp::strtod base::StringToDouble base::internal::JSONParser::ConsumeNumber Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_ubsan&range=395640:395746 Fixed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_ubsan&range=413961:414068 Minimized Testcase (0.01 Kb): Download: https://cluster-fuzz.appspot.com/download/AMIfv97iqaElfgzEOXGJomjvCDOOwRbLxGNEVWPyFA_I_dTlfWwQYB4tBXtkwex_LIvvr0mY5lgbqLjHYEs-VlSstdzYplNu9R-Zpgrn7jEkfGnFhOJz-5XpZ6Gf7ac1Csa6bWo-I0tueXfb4Sl48OnUrZ6j021vVg?testcase_id=4514552998002688 9e5290015000 See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Aug 25 2016
ClusterFuzz has detected this issue as fixed in range 413961:414068. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6351706208337920 Fuzzer: libfuzzer_base_json_reader_fuzzer Job Type: libfuzzer_chrome_ubsan Platform Id: linux Crash Type: Integer-overflow Crash Address: Crash State: dmg_fp::strtod base::StringToDouble base::internal::JSONParser::ConsumeNumber Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_ubsan&range=395640:395746 Fixed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_ubsan&range=413961:414068 Minimized Testcase (0.01 Kb): Download: https://cluster-fuzz.appspot.com/download/AMIfv97JnS77FRiL82iSJeHxjlFKDRuMan_I8fEb1UZ3Fi55XaW2jt_Qim9IWrjBiScosI25FNlz47aw8N0lj1sQNGfVKDfAFPJl26sa06SPYb506dvAU4WoYuAd2RB_5IRlZIzTiZq-IziztnYq1XNg6StcLjpgbQ?testcase_id=6351706208337920 9e5290015000 See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Aug 25 2016
Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6079368462073856 Fuzzer: libfuzzer_string_to_int_fuzzer Job Type: libfuzzer_chrome_ubsan Platform Id: linux Crash Type: Integer-overflow Crash Address: Crash State: dmg_fp::strtod base::StringToDouble _start Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_ubsan&range=414214:414310 Minimized Testcase (0.01 Kb): Download: https://cluster-fuzz.appspot.com/download/AMIfv96e_NzbswN_6GqCAnGnT6YRoEl9Bzly3mANHb-oULyB7nSi10kxLhLCgKg-VLUfdHJk0Z0szfW9Qk2HFL-elO-CoMY53KuGfsoQXbaacD7j-ZbY2EiEX9GMt6iBLCzfRROfCCuq0yOdCWcizEhFiwpm1tdHcg?testcase_id=6079368462073856 00E4000000000 Issue manually filed by: mmohammad See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.
,
Aug 26 2016
ClusterFuzz has detected this issue as fixed in range 414399:414444. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6079368462073856 Fuzzer: libfuzzer_string_to_int_fuzzer Job Type: libfuzzer_chrome_ubsan Platform Id: linux Crash Type: Integer-overflow Crash Address: Crash State: dmg_fp::strtod base::StringToDouble _start Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_ubsan&range=414214:414310 Fixed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_ubsan&range=414399:414444 Minimized Testcase (0.01 Kb): Download: https://cluster-fuzz.appspot.com/download/AMIfv96e_NzbswN_6GqCAnGnT6YRoEl9Bzly3mANHb-oULyB7nSi10kxLhLCgKg-VLUfdHJk0Z0szfW9Qk2HFL-elO-CoMY53KuGfsoQXbaacD7j-ZbY2EiEX9GMt6iBLCzfRROfCCuq0yOdCWcizEhFiwpm1tdHcg?testcase_id=6079368462073856 00E4000000000 See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Aug 26 2016
ClusterFuzz testcase is verified as fixed, closing issue. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
,
Nov 22 2016
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
|||
►
Sign in to add a comment |
|||
Comment 1 by brajkumar@chromium.org
, Jul 14 2016Owner: dcheng@chromium.org
Status: Assigned (was: Available)