Issue metadata
Sign in to add a comment
|
Heap-buffer-overflow in _cmsDupMem |
||||||||||||||||||||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=6637491094552576 Fuzzer: afl_pdf_codec_icc_fuzzer Job Type: afl_chrome_asan Platform Id: linux Crash Type: Heap-buffer-overflow READ {*} Crash Address: 0x602000000200 Crash State: _cmsDupMem MatrixElemDup cmsStageDup Recommended Security Severity: Medium Minimized Testcase (0.60 Kb): https://cluster-fuzz.appspot.com/download/AMIfv96SaEw6DTzqSaDWFa05tyRGH4irgXEfejZ0z2HVZjWe31MHsMhg8I8klGdj-5vfX_TG5kSE73qHn-57driCpX39WmJy7c6Yy9FNBd1WUtyV6nVyKYsDFU3VSyyegat2yVj5nHd7zSVE5-McCU_4fBJZ5ec8sA?testcase_id=6637491094552576 Issue filed automatically. See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.
,
Oct 6 2016
ClusterFuzz has detected this issue as fixed in range 422996:423075. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6637491094552576 Fuzzer: afl_pdf_codec_icc_fuzzer Job Type: afl_chrome_asan Platform Id: linux Crash Type: Heap-buffer-overflow READ {*} Crash Address: 0x602000000200 Crash State: _cmsDupMem MatrixElemDup cmsStageDup Recommended Security Severity: Medium Fixed: https://cluster-fuzz.appspot.com/revisions?job=afl_chrome_asan&range=422996:423075 Minimized Testcase (0.60 Kb): https://cluster-fuzz.appspot.com/download/AMIfv96SaEw6DTzqSaDWFa05tyRGH4irgXEfejZ0z2HVZjWe31MHsMhg8I8klGdj-5vfX_TG5kSE73qHn-57driCpX39WmJy7c6Yy9FNBd1WUtyV6nVyKYsDFU3VSyyegat2yVj5nHd7zSVE5-McCU_4fBJZ5ec8sA?testcase_id=6637491094552576 See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Jan 13 2017
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
|||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||
Comment 1 by tsepez@chromium.org
, Oct 5 2016Status: Duplicate (was: Untriaged)