Issue metadata
Sign in to add a comment
|
Heap-buffer-overflow in CGifLZWDecoder::ClearTable |
||||||||||||||||||||||||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=5265857690468352 Fuzzer: libfuzzer_pdf_codec_gif_fuzzer Job Type: libfuzzer_chrome_asan_debug Platform Id: linux Crash Type: Heap-buffer-overflow WRITE 1 Crash Address: 0x62a000005232 Crash State: CGifLZWDecoder::ClearTable CGifLZWDecoder::InitTable gif_load_frame Recommended Security Severity: High Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_asan_debug&range=400732:400874 Minimized Testcase (0.04 Kb): https://cluster-fuzz.appspot.com/download/AMIfv96iM08Um7DUOyAeksputdPKUqGx219SQT5_d6IQ_SdoSgbub5MkgAykeb5oO-7WO7pfrPfuaRgwb7b8y-i9tYnBXuv_V6oB5WQ_G7We3Hy8QG_w975Kgjb52Wdiwd3wSnY1BZWbiWbkEj51WipaHOERJOFRJg?testcase_id=5265857690468352 Issue filed automatically. See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.
,
Nov 7 2016
,
Nov 7 2016
thestig -- Can you take a look? This affects stable, and doesn't have a clear culprit CL for the regression.
,
Nov 7 2016
,
Jan 11 2017
ClusterFuzz has detected this issue as fixed in range 442671:442734. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5265857690468352 Fuzzer: libfuzzer_pdf_codec_gif_fuzzer Job Type: libfuzzer_chrome_asan_debug Platform Id: linux Crash Type: Heap-buffer-overflow WRITE 1 Crash Address: 0x62a000005232 Crash State: CGifLZWDecoder::ClearTable CGifLZWDecoder::InitTable gif_load_frame Sanitizer: address (ASAN) Recommended Security Severity: High Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_asan_debug&range=400732:400874 Fixed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_asan_debug&range=442671:442734 Minimized Testcase (0.04 Kb): https://cluster-fuzz.appspot.com/download/AMIfv96iM08Um7DUOyAeksputdPKUqGx219SQT5_d6IQ_SdoSgbub5MkgAykeb5oO-7WO7pfrPfuaRgwb7b8y-i9tYnBXuv_V6oB5WQ_G7We3Hy8QG_w975Kgjb52Wdiwd3wSnY1BZWbiWbkEj51WipaHOERJOFRJg?testcase_id=5265857690468352 See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
May 9 2018
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
|||||||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||||||
Comment 1 by sheriffbot@chromium.org
, Nov 7 2016