Issue metadata
Sign in to add a comment
|
Integer-overflow in chrome_pdf::PDFiumPage::PageToScreen |
||||||||||||||||||||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=5150145832550400 Fuzzer: ochang_search_index_mutator Job Type: linux_ubsan_chrome Platform Id: linux Crash Type: Integer-overflow Crash Address: Crash State: chrome_pdf::PDFiumPage::PageToScreen chrome_pdf::PDFiumPage::GetLink chrome_pdf::PDFiumPage::GetCharIndex Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_ubsan_chrome&range=410916:411073 Minimized Testcase (264.13 Kb): https://cluster-fuzz.appspot.com/download/AMIfv94mQBe0TAwJV0MMlMuazHFWAhI2D5b7ZrStryHtUED_A5ajehv0TvvpC1ba4KUCr_q66e4B0Y_AypCJJxbSslZ-zrcegHUp-tAozNlgLgbAWasQa20c9OnEJp6FN7u7r6L_R7acJWHh_-XndPhpJzwEjPh7W87L4svqsEVA4GB3VrwZDiQ?testcase_id=5150145832550400 Additional requirements: Requires Gestures Issue manually filed by: kavvaru See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Sep 27 2016
,
Sep 28 2016
ClusterFuzz has detected this issue as fixed in range 421240:421431. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5150145832550400 Fuzzer: ochang_search_index_mutator Job Type: linux_ubsan_chrome Platform Id: linux Crash Type: Integer-overflow Crash Address: Crash State: chrome_pdf::PDFiumPage::PageToScreen chrome_pdf::PDFiumPage::GetLink chrome_pdf::PDFiumPage::GetCharIndex Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_ubsan_chrome&range=410916:411073 Fixed: https://cluster-fuzz.appspot.com/revisions?job=linux_ubsan_chrome&range=421240:421431 Minimized Testcase (264.13 Kb): https://cluster-fuzz.appspot.com/download/AMIfv94mQBe0TAwJV0MMlMuazHFWAhI2D5b7ZrStryHtUED_A5ajehv0TvvpC1ba4KUCr_q66e4B0Y_AypCJJxbSslZ-zrcegHUp-tAozNlgLgbAWasQa20c9OnEJp6FN7u7r6L_R7acJWHh_-XndPhpJzwEjPh7W87L4svqsEVA4GB3VrwZDiQ?testcase_id=5150145832550400 Additional requirements: Requires Gestures See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Sep 28 2016
The following revision refers to this bug: https://chromium.googlesource.com/chromium/src.git/+/7253c367c1fdf94da3b299f13c6140b815b72da3 commit 7253c367c1fdf94da3b299f13c6140b815b72da3 Author: thestig <thestig@chromium.org> Date: Tue Sep 27 22:47:13 2016 Sanitize values in chrome_pdf::PDFiumPage::PageToScreen(). BUG= 650167 Review-Url: https://codereview.chromium.org/2374643002 Cr-Commit-Position: refs/heads/master@{#421370} [modify] https://crrev.com/7253c367c1fdf94da3b299f13c6140b815b72da3/pdf/pdfium/pdfium_page.cc
,
Nov 22 2016
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
|||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||
Comment 1 by kavvaru@chromium.org
, Sep 26 2016Labels: -Type-Bug M-55 Te-Logged Type-Bug-Regression
Owner: thestig@chromium.org
Status: Assigned (was: Untriaged)