Issue metadata
Sign in to add a comment
|
Heap-buffer-overflow in webrtc::AddSctpDataCodec |
||||||||||||||||||||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=4506802647728128 Fuzzer: afl_sdp_parser_fuzzer Job Type: afl_chrome_asan Platform Id: linux Crash Type: Heap-buffer-overflow READ 4 Crash Address: 0x611000000ca8 Crash State: webrtc::AddSctpDataCodec webrtc::ParseContent webrtc::SdpDeserialize Regressed: https://cluster-fuzz.appspot.com/revisions?job=afl_chrome_asan&range=419151:419192 Minimized Testcase (0.61 Kb): Download: https://cluster-fuzz.appspot.com/download/AMIfv97FJbt4rkY95cNZzpPFWj7uhwgR3wNqZsgiXJLka81HXkl4sU_RJRPU66yAFp7t0HFoRwQ1XijoM0REwiSP3Hxx5THWRsiGReLBNTbqe96dxYtIR5ZYb9tjFqeMk8OB4Y6uBuGzrukltP11D1nfe4ryx-bS9Q?testcase_id=4506802647728128 v=0 o=mozilla...THIR��-23.0.1 5115930group144083302970 0 IN IP4 0.0 s=- t=0 0 a=ice-options:tle m=audio 9 UD:21216693v0 cna} m=videocation 9 DTLS/SCTP/TLS/RTP/SAVPF 1r0 12-mux0 a=P8/9 a=rtcp-fb:97 nack/90000 a=r2symmetry-allowedmux a=so=mozilla...THIR��-23. a=rtpmap:1;0 VP8/9 a=rtcp-fb:97 nack pli-mux a=rtpmap:1;0 VP8/9 a=rtcp-fb:97 nack/90000 a=rtpSAVPtry-allowedmux a=sctp-portrtpmap:1;0 VP8/9 a=rtpmap:12v H265/90000 a=rtpCTP/TLS/6 :97 ccm fir a=rtcp-mux a=rtpmap:1;0 VP8/9 a=rtcp-fb:97 nack pli-mux a=rtpmap:1;0 VP8/9 a=r97 c=I0 a=seportrtpmap:1;0 VP8/9 a=rtpmap:12v H265/90000 a=rtpCTP/SAVPF 1r0 126 97 c=I0 a=see=1 Issue filed automatically. See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.
,
Oct 5 2016
ClusterFuzz has detected this issue as fixed in range 422775:422831. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=4506802647728128 Fuzzer: afl_sdp_parser_fuzzer Job Type: afl_chrome_asan Platform Id: linux Crash Type: Heap-buffer-overflow READ 4 Crash Address: 0x611000000ca8 Crash State: webrtc::AddSctpDataCodec webrtc::ParseContent webrtc::SdpDeserialize Regressed: https://cluster-fuzz.appspot.com/revisions?job=afl_chrome_asan&range=419151:419192 Fixed: https://cluster-fuzz.appspot.com/revisions?job=afl_chrome_asan&range=422775:422831 Minimized Testcase (0.61 Kb): Download: https://cluster-fuzz.appspot.com/download/AMIfv97FJbt4rkY95cNZzpPFWj7uhwgR3wNqZsgiXJLka81HXkl4sU_RJRPU66yAFp7t0HFoRwQ1XijoM0REwiSP3Hxx5THWRsiGReLBNTbqe96dxYtIR5ZYb9tjFqeMk8OB4Y6uBuGzrukltP11D1nfe4ryx-bS9Q?testcase_id=4506802647728128 v=0 o=mozilla...THIR��-23.0.1 5115930group144083302970 0 IN IP4 0.0 s=- t=0 0 a=ice-options:tle m=audio 9 UD:21216693v0 cna} m=videocation 9 DTLS/SCTP/TLS/RTP/SAVPF 1r0 12-mux0 a=P8/9 a=rtcp-fb:97 nack/90000 a=r2symmetry-allowedmux a=so=mozilla...THIR��-23. a=rtpmap:1;0 VP8/9 a=rtcp-fb:97 nack pli-mux a=rtpmap:1;0 VP8/9 a=rtcp-fb:97 nack/90000 a=rtpSAVPtry-allowedmux a=sctp-portrtpmap:1;0 VP8/9 a=rtpmap:12v H265/90000 a=rtpCTP/TLS/6 :97 ccm fir a=rtcp-mux a=rtpmap:1;0 VP8/9 a=rtcp-fb:97 nack pli-mux a=rtpmap:1;0 VP8/9 a=r97 c=I0 a=seportrtpmap:1;0 VP8/9 a=rtpmap:12v H265/90000 a=rtpCTP/SAVPF 1r0 126 97 c=I0 a=see=1 See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Oct 5 2016
ClusterFuzz has detected this issue as fixed in range 422775:422831. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=4506802647728128 Fuzzer: afl_sdp_parser_fuzzer Job Type: afl_chrome_asan Platform Id: linux Crash Type: Heap-buffer-overflow READ 4 Crash Address: 0x611000000ca8 Crash State: webrtc::AddSctpDataCodec webrtc::ParseContent webrtc::SdpDeserialize Regressed: https://cluster-fuzz.appspot.com/revisions?job=afl_chrome_asan&range=419151:419192 Fixed: https://cluster-fuzz.appspot.com/revisions?job=afl_chrome_asan&range=422775:422831 Minimized Testcase (0.61 Kb): Download: https://cluster-fuzz.appspot.com/download/AMIfv97FJbt4rkY95cNZzpPFWj7uhwgR3wNqZsgiXJLka81HXkl4sU_RJRPU66yAFp7t0HFoRwQ1XijoM0REwiSP3Hxx5THWRsiGReLBNTbqe96dxYtIR5ZYb9tjFqeMk8OB4Y6uBuGzrukltP11D1nfe4ryx-bS9Q?testcase_id=4506802647728128 v=0 o=mozilla...THIR��-23.0.1 5115930group144083302970 0 IN IP4 0.0 s=- t=0 0 a=ice-options:tle m=audio 9 UD:21216693v0 cna} m=videocation 9 DTLS/SCTP/TLS/RTP/SAVPF 1r0 12-mux0 a=P8/9 a=rtcp-fb:97 nack/90000 a=r2symmetry-allowedmux a=so=mozilla...THIR��-23. a=rtpmap:1;0 VP8/9 a=rtcp-fb:97 nack pli-mux a=rtpmap:1;0 VP8/9 a=rtcp-fb:97 nack/90000 a=rtpSAVPtry-allowedmux a=sctp-portrtpmap:1;0 VP8/9 a=rtpmap:12v H265/90000 a=rtpCTP/TLS/6 :97 ccm fir a=rtcp-mux a=rtpmap:1;0 VP8/9 a=rtcp-fb:97 nack pli-mux a=rtpmap:1;0 VP8/9 a=r97 c=I0 a=seportrtpmap:1;0 VP8/9 a=rtpmap:12v H265/90000 a=rtpCTP/SAVPF 1r0 126 97 c=I0 a=see=1 See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Jan 12 2017
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
|||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||
Comment 1 by kenrb@chromium.org
, Sep 28 2016Status: Duplicate (was: Untriaged)