Integer-overflow in sqlite3MulInt64 |
|||||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=4624714624663552 Fuzzer: libfuzzer_sqlite3_prepare_v2_fuzzer Job Type: libfuzzer_chrome_ubsan Platform Id: linux Crash Type: Integer-overflow Crash Address: Crash State: sqlite3MulInt64 sqlite3VdbeExec sqlite3Step Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_ubsan&range=415587:415619 Minimized Testcase (0.03 Kb): Download: https://cluster-fuzz.appspot.com/download/AMIfv97Lt2nL30yh-nvitrHw-FKH8-cQbx8uTrRlaZQ-CT_tJgV5_akE2gmmguJznKrnIpHC9fSY4W-CsEkaH5G85sGScocvClKiYAlr_EiQPl5XB5rI4_yGhG0q0h9TQtkoXFnVTw4wISCtvKI7PyRP5pZANz2zAg?testcase_id=4624714624663552 (SELECT 3452005775[a]WHERE a+a*A Issue manually filed by: msrchandra See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.
,
Sep 7 2016
shess@: can you take a look?
,
Sep 29 2016
ClusterFuzz has detected this issue as fixed in range 421501:421558. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=4624714624663552 Fuzzer: libfuzzer_sqlite3_prepare_v2_fuzzer Job Type: libfuzzer_chrome_ubsan Platform Id: linux Crash Type: Integer-overflow Crash Address: Crash State: sqlite3MulInt64 sqlite3VdbeExec sqlite3Step Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_ubsan&range=415587:415619 Fixed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_ubsan&range=421501:421558 Minimized Testcase (0.03 Kb): Download: https://cluster-fuzz.appspot.com/download/AMIfv97Lt2nL30yh-nvitrHw-FKH8-cQbx8uTrRlaZQ-CT_tJgV5_akE2gmmguJznKrnIpHC9fSY4W-CsEkaH5G85sGScocvClKiYAlr_EiQPl5XB5rI4_yGhG0q0h9TQtkoXFnVTw4wISCtvKI7PyRP5pZANz2zAg?testcase_id=4624714624663552 (SELECT 3452005775[a]WHERE a+a*A See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Sep 29 2016
ClusterFuzz testcase is verified as fixed, closing issue. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
,
Oct 18 2016
,
Nov 22 2016
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
|||||
►
Sign in to add a comment |
|||||
Comment 1 by msrchandra@chromium.org
, Sep 1 2016Labels: findit-wrong Te-Logged
Owner: js...@chromium.org
Status: Assigned (was: Untriaged)