Issue metadata
Sign in to add a comment
|
Integer-overflow in blink::WebViewImpl::paint |
||||||||||||||||||||||||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=5851218855591936 Fuzzer: inferno_twister Job Type: linux_ubsan_chrome Platform Id: linux Crash Type: Integer-overflow Crash Address: Crash State: blink::WebViewImpl::paint WebViewPlugin::paint blink::WebPluginContainerImpl::paint Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_ubsan_chrome&range=370022:370027 Minimized Testcase (0.59 Kb): https://cluster-fuzz.appspot.com/download/AMIfv966ISZkjgZCsSXcf_CHIVwCva7WzzblrkHr0jLpD4B1iGKGJSpKD6ShGFm-CI6LhUbzRvMX7ZOpqx3v_n2mdvgvJ7_7vEvMc0vMVH41nuCJbg4fOaR1qd9RBZKA-h4BHI5bjCCi6AF9WP1W0tam5VgV2t4s0w?testcase_id=5851218855591936 Issue manually filed by: kavvaru See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Sep 19 2016
,
Sep 19 2016
,
Sep 19 2016
@qinmin, we may want to merge this into https://crbug.com/640071 .
,
Sep 19 2016
my last CL is 2012, which is probably not related
,
Nov 22 2016
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Mar 30 2017
ClusterFuzz has detected this issue as fixed in range 460287:460297. Detailed report: https://clusterfuzz.com/testcase?key=5851218855591936 Fuzzer: inferno_twister Job Type: linux_ubsan_chrome Platform Id: linux Crash Type: Integer-overflow Crash Address: Crash State: blink::WebViewImpl::paint WebViewPlugin::paint blink::WebPluginContainerImpl::paint Sanitizer: undefined (UBSAN) Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_chrome&range=370022:370027 Fixed: https://clusterfuzz.com/revisions?job=linux_ubsan_chrome&range=460287:460297 Reproducer Testcase: https://clusterfuzz.com/download/AMIfv966ISZkjgZCsSXcf_CHIVwCva7WzzblrkHr0jLpD4B1iGKGJSpKD6ShGFm-CI6LhUbzRvMX7ZOpqx3v_n2mdvgvJ7_7vEvMc0vMVH41nuCJbg4fOaR1qd9RBZKA-h4BHI5bjCCi6AF9WP1W0tam5VgV2t4s0w?testcase_id=5851218855591936 See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page. |
|||||||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||||||
Comment 1 by kavvaru@chromium.org
, Sep 19 2016Labels: M-54 Findit-for-crash
Owner: qin...@chromium.org
Status: Assigned (was: Untriaged)