Issue metadata
Sign in to add a comment
|
Heap-use-after-free in FORM_DoDocumentAAction |
||||||||||||||||||||||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=5938081972879360 Fuzzer: tokenfuzz_pdf_april16 Job Type: linux_asan_pdfium Platform Id: linux Crash Type: Heap-use-after-free READ 8 Crash Address: 0x60700000b578 Crash State: FORM_DoDocumentAAction RenderPdf CPDF_IndirectObjectHolder::AddIndirectObject Recommended Security Severity: High Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_pdfium&range=412760:412915 Minimized Testcase (14.57 Kb): https://cluster-fuzz.appspot.com/download/AMIfv95xX772s0c_KJJmfIMh-0l2YlTgx183UKmpiYQW51fGkUqOA0shiPE3sa9bRc2ucqV810PVX0ELLqrNyoQ9svkop_1Iz0IDTWcUXMXytzc_ACBGHAkvT7i2Ih32sFu5EL8DrcFtc1FyiYZR_VgK_UZ2EG6yag?testcase_id=5938081972879360 Issue manually filed by: inferno See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Aug 23 2016
ClusterFuzz testcase is verified as fixed, closing issue. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
,
Aug 23 2016
,
Aug 23 2016
CF is correct here, looks like the revert was https://pdfium.googlesource.com/pdfium/+/8d6c929d2605dc568beb73aab2c585622947fee2
,
Nov 29 2016
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
May 15 2017
,
Jul 28
|
|||||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||||
Comment 1 by ClusterFuzz
, Aug 23 2016