Undefined-shift in opj_get_all_encoding_parameters |
|||||||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=4744148382121984 Fuzzer: libfuzzer_pdf_jpx_fuzzer Job Type: libfuzzer_chrome_ubsan Platform Id: linux Crash Type: Undefined-shift Crash Address: Crash State: opj_get_all_encoding_parameters opj_pi_create_decode opj_t2_decode_packets Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_ubsan&range=395640:395746 Minimized Testcase (0.22 Kb): https://cluster-fuzz.appspot.com/download/AMIfv94yUkS4yThKlWA9z4a-LtzzPSXf-KGx5UpBoCyfnsg5s0mdGHdTdRUzsZKLJdG57gYaWX2Ad_ln8mJB7dsOsq_riVNcTPsNbk3IxjKTDaGzhy8iLXMSqmHL6vlwAsD7OqrlCReN4b1vmhann_L6suzyHTIRsQ?testcase_id=4744148382121984 Issue filed automatically. See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.
,
Nov 21 2016
The problem is at CJPX_Decoder::Init(unsigned char const*, unsigned int) third_party/pdfium/core/fxcodec/codec/fx_codec_jpx_opj.cpp:773 Oliver, do you have time to take a look at this? If not, feel free to assign back.
,
Nov 21 2016
Sorry, don't have time for this :(
,
Nov 22 2016
Removing EditIssue view restrictions from ClusterFuzz filed bugs. If you believe that this issue should still be restricted, please reapply the label. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Dec 12 2016
,
Dec 12 2016
,
Jan 4 2017
Not sure what the right way to fix this is, and it doesn't seem to be solved upstream. Will take a look later, or anyone feel free to take this.
,
Jan 16 2017
Filed a bug on github: https://github.com/uclouvain/openjpeg/issues/885
,
May 5 2017
ClusterFuzz has detected this issue as fixed in range 469455:469504. Detailed report: https://clusterfuzz.com/testcase?key=4744148382121984 Fuzzer: libfuzzer_pdf_jpx_fuzzer Job Type: libfuzzer_chrome_ubsan Platform Id: linux Crash Type: Undefined-shift Crash Address: Crash State: opj_get_all_encoding_parameters opj_pi_create_decode opj_t2_decode_packets Sanitizer: undefined (UBSAN) Regressed: https://clusterfuzz.com/revisions?job=libfuzzer_chrome_ubsan&range=395640:395746 Fixed: https://clusterfuzz.com/revisions?job=libfuzzer_chrome_ubsan&range=469455:469504 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4744148382121984 See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
May 5 2017
ClusterFuzz testcase 4744148382121984 is verified as fixed, so closing issue. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
,
Jun 16 2017
Bugdroid forgot to mention this was fixed in https://pdfium.googlesource.com/pdfium/+/34f735c9ef34b3bb6493016c7fbeb6df76cf31f5 |
|||||||
►
Sign in to add a comment |
|||||||
Comment 1 by ajha@chromium.org
, Nov 21 2016Labels: M-55