Undefined-shift in t1_decoder_parse_charstrings |
|||||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=6500165685084160 Fuzzer: libfuzzer_pdfium_fuzzer Job Type: libfuzzer_chrome_ubsan Platform Id: linux Crash Type: Undefined-shift Crash Address: Crash State: t1_decoder_parse_charstrings T1_Parse_Glyph_And_Get_Char_String T1_Parse_Glyph Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_ubsan&range=397764:398208 Minimized Testcase (1.07 Kb): https://cluster-fuzz.appspot.com/download/AMIfv97sozqIqNtIGlVvow0t_7SOUJ4xL1BrRUIJt_m_o0djM3rmyTObyGTyYaPXyrh9jPPsfM-uqyMP8hqasAQy-ZkQPAEoiVhjDaIxElSoo_SnAVmpu0mDj06enTQIqoXvq8sZyZp6vIan0yiIpcM92J7NETMyHg?testcase_id=6500165685084160 Issue manually filed by: ajha See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.
,
Aug 18 2016
,
Aug 18 2016
This is a PDF -- reassigning there (not a blink issue)
,
Aug 18 2016
Yet another case where we shouldn't be using the old freetype from third_party/freetype.
,
Nov 22 2016
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Feb 28 2017
ClusterFuzz has detected this issue as fixed in range 453205:453227. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6500165685084160 Fuzzer: libfuzzer_pdfium_fuzzer Job Type: libfuzzer_chrome_ubsan Platform Id: linux Crash Type: Undefined-shift Crash Address: Crash State: t1_decoder_parse_charstrings T1_Parse_Glyph_And_Get_Char_String T1_Face_Init Sanitizer: undefined (UBSAN) Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_ubsan&range=397764:398208 Fixed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_ubsan&range=453205:453227 Reproducer Testcase: https://cluster-fuzz.appspot.com/download/AMIfv947GDjsGHSmtGjeVENAC7Idr7yyOhTyiRlvtqJpv8AJQHJisBrYR3TzoPMhnqmzFSUo_vQi7eyjyXOXPShyHEO_2TNQrHXp9JfK9rAqezE_CfaajCboU0HZQSgwew7AXYyrKle3V5BtBDFGTxyN0kvuS4zZ641RRQ-x0ODU9buyDkAYbNvS8NRPxM7WzhnLAvIvk6zQTwDB_b-XcWV1AZoQIjNFOnrJR72pdYNx4rqeBHp924fx0ueoTjuL8IMuyd2hsqMzdnhkaf3F1hxmUFEP94wQSQ5xTKSXRa3v_UkJWJfSZU-CgiNK7y_tpCIwowdYxpQ8zTtOE1P6EtbHVt6nyV_3idFlHlSlOLkrdB4LzSS6ycg?testcase_id=6500165685084160 See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page. |
|||||
►
Sign in to add a comment |
|||||
Comment 1 by ajha@chromium.org
, Aug 18 2016Labels: Needs-triage Te-Logged M-53