New issue
Advanced search Search tips

Issue 652012 link

Starred by 1 user

Issue metadata

Status: Duplicate
Merged: issue 648069
Owner:
Closed: Oct 2016
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 1
Type: Bug-Security



Sign in to add a comment

Negative-size-param in sfntly::MemoryByteArray::InternalGet

Project Member Reported by ClusterFuzz, Oct 1 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6020028409577472

Fuzzer: afl_sfntly_fuzzer
Job Type: afl_chrome_asan
Platform Id: linux

Crash Type: Negative-size-param
Crash Address: 
Crash State:
  sfntly::MemoryByteArray::InternalGet
  sfntly::NameTable::Name
  sfntly::SubsetterImpl::LoadFont
  
Regressed: https://cluster-fuzz.appspot.com/revisions?job=afl_chrome_asan&range=417009:417261

Minimized Testcase (1.72 Kb): https://cluster-fuzz.appspot.com/download/AMIfv97PmJiOaDRavQkV155mV0heNDHIrSw3oPRk2FE-1MmAiFzs_4QMgJz9zHPbB_hGV6ddb3fT9Vlz_MZeF-FY0WWVOHdWT-bTX0GEAENFHftJixCVoQVOeIuTyl5b-JmbQ-FriyTENBloDq-g-MuL1g-1M2yLEQ?testcase_id=6020028409577472

Issue filed automatically.

See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.
 

Comment 1 by kenrb@chromium.org, Oct 1 2016

Cc: kenrb@chromium.org behdad@chromium.org
Components: UI>Internationalization
Labels: Pri-1
Owner: thestig@chromium.org
Status: Assigned (was: Untriaged)
thestig@: Can you please take a look at this sfntly fuzzer bug? Cluster-fuzz' regression range includes this sfntly roll: https://chromium.googlesource.com/external/github.com/googlei18n/sfntly/+log/b18b09b..1ef790a

(By the way, is there a crbug component for sfntly? The best I could find was UI>Internationalization which might not be right)
Components: -UI>Internationalization Internals>Skia>PDF
Mergedinto: 648069
Status: Duplicate (was: Assigned)
Been busy with other bugs. These bugs probably have existed for years, BTW.
Project Member

Comment 3 by sheriffbot@chromium.org, Jan 27 2017

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment