pTiffContext->offset() <= (uint32_t)pTiffContext->io_in()->GetSize() |
|||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=4533882671333376 Fuzzer: libfuzzer_pdf_codec_tiff_fuzzer Job Type: libfuzzer_chrome_asan_debug Platform Id: linux Crash Type: ASSERT Crash Address: Crash State: pTiffContext->offset() <= (uint32_t)pTiffContext->io_in()->GetSize() tiff_seek TIFFFetchDirectory Minimized Testcase (0.00 Kb): https://cluster-fuzz.appspot.com/download/AMIfv96pDBjRdfgFqqSynO929VQOM5eAXMeWE7Ed3iCVySNz3RNLgdyMUgvROP92n3vg6A4a-Ge24vX6UBqdZ_4KbquVwAoQKy5FVlUb8h1jW13NdDaE-yTyoWG_qPSoRx6RaJ24-26Y5K4gi7rwbSjXlacqBgi7AA?testcase_id=4533882671333376 Issue filed automatically. See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.
,
Oct 26 2016
,
Oct 26 2016
The following revision refers to this bug: https://pdfium.googlesource.com/pdfium.git/+/cd5f026e7b277ec73d53e149c7c48ee981547d1a commit cd5f026e7b277ec73d53e149c7c48ee981547d1a Author: thestig <thestig@chromium.org> Date: Wed Oct 26 20:41:26 2016 Add more checks to tiff_read() and tiff_seek(). BUG= chromium:659519 Review-Url: https://codereview.chromium.org/2456553002 [modify] https://crrev.com/cd5f026e7b277ec73d53e149c7c48ee981547d1a/core/fxcodec/codec/fx_codec_tiff.cpp
,
Oct 26 2016
,
Oct 26 2016
The following revision refers to this bug: https://chromium.googlesource.com/chromium/src.git/+/afce6ae2a6c8d41f8327d29f18d8fb918781d92e commit afce6ae2a6c8d41f8327d29f18d8fb918781d92e Author: pdfium-deps-roller <pdfium-deps-roller@chromium.org> Date: Wed Oct 26 23:08:14 2016 Roll src/third_party/pdfium/ d3a2009d7..cd5f026e7 (1 commit). https://pdfium.googlesource.com/pdfium.git/+log/d3a2009d75ea..cd5f026e7b27 $ git log d3a2009d7..cd5f026e7 --date=short --no-merges --format='%ad %ae %s' 2016-10-26 thestig Add more checks to tiff_read() and tiff_seek(). BUG= 659519 Documentation for the AutoRoller is here: https://skia.googlesource.com/buildbot/+/master/autoroll/README.md If the roll is causing failures, see: http://www.chromium.org/developers/tree-sheriffs/sheriff-details-chromium#TOC-Failures-due-to-DEPS-rolls TBR=dsinclair@chromium.org Review-Url: https://codereview.chromium.org/2449853007 Cr-Commit-Position: refs/heads/master@{#427863} [modify] https://crrev.com/afce6ae2a6c8d41f8327d29f18d8fb918781d92e/DEPS
,
Oct 27 2016
ClusterFuzz has detected this issue as fixed in range 427846:427885. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=4533882671333376 Fuzzer: libfuzzer_pdf_codec_tiff_fuzzer Job Type: libfuzzer_chrome_asan_debug Platform Id: linux Crash Type: ASSERT Crash Address: Crash State: pTiffContext->offset() <= (uint32_t)pTiffContext->io_in()->GetSize() tiff_seek TIFFFetchDirectory Fixed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_asan_debug&range=427846:427885 Minimized Testcase (0.00 Kb): https://cluster-fuzz.appspot.com/download/AMIfv96pDBjRdfgFqqSynO929VQOM5eAXMeWE7Ed3iCVySNz3RNLgdyMUgvROP92n3vg6A4a-Ge24vX6UBqdZ_4KbquVwAoQKy5FVlUb8h1jW13NdDaE-yTyoWG_qPSoRx6RaJ24-26Y5K4gi7rwbSjXlacqBgi7AA?testcase_id=4533882671333376 See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Nov 22 2016
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
|||
►
Sign in to add a comment |
|||
Comment 1 by durga.behera@chromium.org
, Oct 26 2016Owner: thestig@chromium.org
Status: Assigned (was: Untriaged)