New issue
Advanced search Search tips

Issue 666618 link

Starred by 1 user

Issue metadata

Status: Duplicate
Merged: issue 675617
Owner:
Closed: Feb 2017
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 2
Type: Bug



Sign in to add a comment

Integer-overflow in Type_MPEmatrix_Read

Project Member Reported by ClusterFuzz, Nov 18 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6017538136997888

Fuzzer: libfuzzer_pdf_codec_icc_fuzzer
Job Type: libfuzzer_chrome_ubsan
Platform Id: linux

Crash Type: Integer-overflow
Crash Address: 
Crash State:
  Type_MPEmatrix_Read
  ReadMPEElem
  ReadPositionTable
  

Minimized Testcase (0.17 Kb): https://cluster-fuzz.appspot.com/download/AMIfv96kG2G66tyNBWtdr9LrbHVkWAJJLwgjBWzjW6_Vgi149DZTcDhMeXjifcKFZv4JNAMrMC_zUk568wcDx_ikT1m4vTvdf0iXgBjMuRYa0ng6hcrlKjcDzYgrinDBwcILt-3KPS3XryoJSLwZrOUZ856HgtNrpQ?testcase_id=6017538136997888

Issue filed automatically.

See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.
 

Comment 1 by ajha@chromium.org, Nov 18 2016

Components: Internals>Plugins>PDF
Labels: M-54
Project Member

Comment 2 by sheriffbot@chromium.org, Nov 22 2016

Labels: -Restrict-View-EditIssue
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Owner: kcwu@chromium.org
Status: Assigned (was: Untriaged)
More lcms fun. kcwu@ if you don't have time please feel free to assign back to me.

Comment 4 by kcwu@chromium.org, Feb 22 2017

Cc: kcwu@chromium.org
Owner: dsinclair@chromium.org
I don't have free time to help. Reassigned.
Project Member

Comment 5 by ClusterFuzz, Feb 23 2017

ClusterFuzz has detected this issue as fixed in range 452123:452182.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6017538136997888

Fuzzer: libfuzzer_pdf_codec_icc_fuzzer
Job Type: libfuzzer_chrome_ubsan
Platform Id: linux

Crash Type: Integer-overflow
Crash Address: 
Crash State:
  Type_MPEmatrix_Read
  ReadMPEElem
  ReadPositionTable
  
Sanitizer: undefined (UBSAN)

Fixed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_ubsan&range=452123:452182

Reproducer Testcase: https://cluster-fuzz.appspot.com/download/AMIfv95ue-OCn9DaCaMaY5mOvatwZY9x9BD0ViRskpsFQxHvUnOaxugMzIcyLE414IVI4Wkvk4jh5mK6p-qtWUI4rfbsrCCH0311DYnBk8ovGq4IKve4d77Ovn1tIWL7JAv4j43dpivemXWqtbHI7gspDI1txGP8O-SafCNrIWa2kIDc2fGUjFKMIzhkM2s0qUEjefxLQA0554HyscWwnp5bThuiGWxQPJ29GeSgU8wkvHq2CDmrdpvkMwHFZQFmqD0qs2Q21RaRWxOfDq7iBKneuRQhoNv9vW6EV6Wd53-5MX1oSHfjwnCDdHeW0NRvKJZnCz0L1i2D1MSRMo5jeoaZZnU7tM4PujGUfmQkuMd3YbQ4vtwVYkQ?testcase_id=6017538136997888


See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.

Comment 6 by npm@chromium.org, Feb 23 2017

Fixed along with  issue 675617 , should I dup? I'm not sure if it will be easy to figure out if there's really a potential integer overflow without the testcase.

Comment 7 by npm@chromium.org, Feb 23 2017

Mergedinto: 675617
Status: Duplicate (was: Assigned)

Sign in to add a comment