Issue metadata
Sign in to add a comment
|
Heap-buffer-overflow in bmp_decode_rle4 |
||||||||||||||||||||||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=5732922532560896 Fuzzer: libfuzzer_pdf_codec_bmp_fuzzer Job Type: libfuzzer_chrome_asan_debug Platform Id: linux Crash Type: Heap-buffer-overflow WRITE 1 Crash Address: 0x6230000018d8 Crash State: bmp_decode_rle4 bmp_decode_image CCodec_BmpModule::LoadImage Recommended Security Severity: High Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_asan_debug&range=398395:399155 Minimized Testcase (0.52 Kb): https://cluster-fuzz.appspot.com/download/AMIfv94cOI9cRaARqZw80oQOFXy303BVbd00RCzL1azGIe1WLAME_m9A4FBqlcg0aEXLh9CN-fRQRhWJ36LORgHNkQbQurAa77nHrPJ51Yu4iXhiAprag_AGxG1GCAF-JMWhakU51P9UW_S6PVf6z-3eaYSlv9o3KQ?testcase_id=5732922532560896 Issue filed automatically. See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.
,
Nov 19 2016
,
Nov 21 2016
Can you please take a look or route this to someone who can? Thanks.
,
Nov 21 2016
XFA is not enabled in any Chrome branch.
,
Jan 2 2017
,
Feb 28 2017
ClusterFuzz has detected this issue as fixed in range 453290:453318. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5732922532560896 Fuzzer: libfuzzer_pdf_codec_bmp_fuzzer Job Type: libfuzzer_chrome_asan_debug Platform Id: linux Crash Type: Heap-buffer-overflow WRITE 1 Crash Address: 0x6230000018d8 Crash State: bmp_decode_rle4 bmp_decode_image CCodec_BmpModule::LoadImage Sanitizer: address (ASAN) Recommended Security Severity: High Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_asan_debug&range=398395:399155 Fixed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_asan_debug&range=453290:453318 Reproducer Testcase: https://cluster-fuzz.appspot.com/download/AMIfv97EYH48mQl9M-pyHBcJPqWkh-gWMliXyiBTPBkpCNPiZG-H1gkf2rlPBJUCodUzs6pgUrbXnhJokQGYx5RQsCrFprBkRrmUfOLObGDT4CeuJw5GU_2V7Zsgs2Bz-qYD6tM4BPg94FLP_gsuBWo6P-l2Raax8SOdxLetNy6G8n3FisIe8COB89KnWmxoOCkNp96KbuEuynBHsQ7LJzwQrF6LQlEUkL_oPYORYbr1QxrfuHBrW1GjN9GH9wr47xX-RkWKR7YlVVkcfWlSa5YHpZWjrpYppr1gPWM9alOALVcdIQAQl-VROfQXB0sDXkXW_Iy71K-Ed0rjiO4oTlNh1qMTmKFpLOSqz7xKJZUcCc9clgJ5tFs?testcase_id=5732922532560896 See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Feb 28 2017
ClusterFuzz testcase 5732922532560896 is verified as fixed, so closing issue. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
,
Mar 1 2017
,
Jun 7 2017
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
|||||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||||
Comment 1 by sheriffbot@chromium.org
, Nov 19 2016