Issue metadata
Sign in to add a comment
|
(expat) Use-of-uninitialized-value in little2_nameMatchesAscii |
||||||||||||||||||||||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=6370553168658432 Fuzzer: libfuzzer_expat_xml_parse_fuzzer Job Type: libfuzzer_chrome_msan Platform Id: linux Crash Type: Use-of-uninitialized-value Crash Address: Crash State: little2_nameMatchesAscii doctype1 doProlog Recommended Security Severity: Medium Minimized Testcase (0.03 Kb): https://cluster-fuzz.appspot.com/download/AMIfv95hkaBJlg9Yl4Ht4StRZCo4gY3xDhRzLGkSbkhIGjielI4nk5IF6GaccNCvfGGUQGwHA56gGzY-X8UlM3zcRMHPA3MWruAQ_6s37nH05Ry3BY54fhlW8n3lXJF_-0p-vVu0-XYbBhkiUYhPqvW4xsMmjLtXdw?testcase_id=6370553168658432 Issue manually filed by: mmoroz See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.
,
Aug 24 2016
,
Aug 24 2016
,
Aug 25 2016
,
Sep 7 2016
nick: Uh oh! This issue still open and hasn't been updated in the last 14 days. This is a serious vulnerability, and we want to ensure that there's progress. Could you please leave an update with the current status and any potential blockers? If you're not the right owner for this issue, could you please remove yourself as soon as possible or help us find the right one? If the issue is fixed or you can't reproduce it, please close the bug. If you've started working on a fix, please set the status to Started. Thanks for your time! To disable nags, add the Disable-Nags label. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Sep 21 2016
nick: Uh oh! This issue still open and hasn't been updated in the last 28 days. This is a serious vulnerability, and we want to ensure that there's progress. Could you please leave an update with the current status and any potential blockers? If you're not the right owner for this issue, could you please remove yourself as soon as possible or help us find the right one? If the issue is fixed or you can't reproduce it, please close the bug. If you've started working on a fix, please set the status to Started. Thanks for your time! To disable nags, add the Disable-Nags label. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Oct 11 2016
The same question as for bug 637228 : should we report it upstream or what is the plan? This is a reproducible issue affecting Stable.
,
Oct 13 2016
,
Nov 2 2016
nick@ or dominicc@, have either of you had a chance to take a look at this bug yet? Thanks!
,
Nov 2 2016
expat seems to be a dependency of libjingle. Despite having originally checked this into chrome (when chrome sync depended on libjingle), I don't know anything about it. A better OWNER, who understands how expat is used, might be someone from this list: https://cs.chromium.org/chromium/src/third_party/webrtc/libjingle/OWNERS
,
Nov 3 2016
I've started an email thread looking for new expat OWNERS based on. The current dependencies are skia->expat (for font parsing) and chromoting->webrtc->skia (for libjingle -- if chromoting stopped depending on libjingle, libjingle could be dropped). + folks responsible for the above to the cc
,
Nov 4 2016
,
Nov 4 2016
Sync still depends on libjingle and libxml through jingle/notifier. AFAIK XMPP is still used in sync tests, but not in prod. CloudPrint uses jingle/notifier as well. In all these cases the XML comes from Google XMPP servers.
,
Dec 2 2016
,
Jan 26 2017
,
Mar 10 2017
,
Mar 24 2017
ClusterFuzz has detected this issue as fixed in range 459012:459028. Detailed report: https://clusterfuzz.com/testcase?key=6370553168658432 Fuzzer: libfuzzer_expat_xml_parse_fuzzer Job Type: libfuzzer_chrome_msan Platform Id: linux Crash Type: Use-of-uninitialized-value Crash Address: Crash State: little2_nameMatchesAscii doctype1 doProlog Sanitizer: memory (MSAN) Recommended Security Severity: Medium Regressed: https://clusterfuzz.com/revisions?job=libfuzzer_chrome_msan&range=411312:411446 Fixed: https://clusterfuzz.com/revisions?job=libfuzzer_chrome_msan&range=459012:459028 Reproducer Testcase: https://clusterfuzz.com/download/AMIfv9697qEIfc1X2by72ggxDrDiWcGaASp8rNbPCaphp3ohwnSk1aLyhzdYM7xn6kIyoKhe4AlkQKs9hIwI-joEKoT_NW2peCADHyZueosROWzneVG4AWQgWot9LaVhgF5UyNa9_6x3qlidvuG5QptTHjjdq0q7F5chNn5zkKFUXVvNkWgkaXfjma8cSOgkrqXadBWBgEV3O7qnN1G3O6GeC_M2eqp5M6Mj1wcgB7JVCdMCCh5VB8RRp2SA4EGgLxEIH9Yresmw58PZCW0pkRgAtCVmVC7Oz9-VedNqVoqmfgcSCSlg9VuiUUsmQaHghKdLHu7HBgpPvRc0gH34TThuzf8HedXjD-3aJgGVPX2YxqG5bnZOhLY?testcase_id=6370553168658432 See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Mar 24 2017
,
Jun 30 2017
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
|||||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||||
Comment 1 by mmoroz@chromium.org
, Aug 24 2016Labels: Pri-1
Owner: nick@chromium.org