Integer-overflow in blink::Document::lastModified |
|||||||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=5823765336555520 Fuzzer: inferno_webbot Job Type: linux_ubsan_chrome Platform Id: linux Crash Type: Integer-overflow Crash Address: Crash State: blink::Document::lastModified blink::DocumentV8Internal::lastModifiedAttributeGetterCallback v8::internal::FunctionCallbackArguments::Call Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_ubsan_chrome&range=370022:370027 Minimized Testcase (0.13 Kb): Download: https://cluster-fuzz.appspot.com/download/AMIfv97FGMnpRYAquH7e8EtMlkNdk9trSMwCYuQpqXRyAFeeuDT3Uj-jwY3MgsTqVjJpT30JyOSt8mtwJbyk3okcERngdsXIR44f54oFYWk9JYZSftwRk-eB5ZK0DRswDbOmnUh2Uk26GQA9iazkh3jgs6MSiG-60g?testcase_id=5823765336555520 <!DOCTYPE html><html><script> window.open("http://travel.org.ua"); window.open(); window.location = "http://katd.org";</script></html> Issue manually filed by: nyerramilli See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Aug 9 2016
This is a DOM bug, but also this test case is really terrible it's loading from the real network? Please don't file overflow bugs without a self contained repro.
,
Aug 12 2016
,
Oct 11 2016
,
Oct 18 2016
,
Nov 22 2016
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Dec 22 2016
ClusterFuzz testcase 5823765336555520 is flaky and no longer reproduces, so closing issue. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue. |
|||||||
►
Sign in to add a comment |
|||||||
Comment 1 by nyerramilli@chromium.org
, Aug 9 2016Components: Tools>Test>FindIt>WrongResult
Labels: findit-wrong Te-Logged M-53
Owner: esprehn@chromium.org
Status: Assigned (was: Untriaged)