Issue metadata
Sign in to add a comment
|
Heap-buffer-overflow in table_r |
||||||||||||||||||||||||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=4759801927303168 Fuzzer: noel-image-surku Job Type: linux_asan_chrome_v8_arm Platform Id: linux Crash Type: Heap-buffer-overflow READ 4 Crash Address: 0xb120cee4 Crash State: table_r color_lookup_table clamp_1 Recommended Security Severity: Medium Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_v8_arm&range=433593:433755 Minimized Testcase (515.05 Kb): https://cluster-fuzz.appspot.com/download/AMIfv95zdkGQhbkPovyvvCx9U3Nmzj0QbJi8Xj_vsbrA2dqQMFoLB2MGlX5QJSjaVkt53_YIgKIQh9KVVHzOkFuzvrciH56yIly7HdcPgag8qtze8lrQ3ZzxgsrcM3NMEgGzvDKCiy23PNc1wuZG1WtUFsjrFF7yapzXmOJxO3JV7uCQ1tMoeow?testcase_id=4759801927303168 Issue filed automatically. See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Nov 22 2016
This issue is a security regression. If you are not able to fix this quickly, please revert the change that introduced it. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Nov 22 2016
,
Nov 22 2016
This looks identical to crbug.com/667695 , merging it in.
,
Nov 23 2016
ClusterFuzz has detected this issue as fixed in range 433807:434033. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=4759801927303168 Fuzzer: noel-image-surku Job Type: linux_asan_chrome_v8_arm Platform Id: linux Crash Type: Heap-buffer-overflow READ 4 Crash Address: 0xb120cee4 Crash State: table_r color_lookup_table clamp_1 Recommended Security Severity: Medium Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_v8_arm&range=433593:433755 Fixed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_v8_arm&range=433807:434033 Minimized Testcase (515.05 Kb): https://cluster-fuzz.appspot.com/download/AMIfv95zdkGQhbkPovyvvCx9U3Nmzj0QbJi8Xj_vsbrA2dqQMFoLB2MGlX5QJSjaVkt53_YIgKIQh9KVVHzOkFuzvrciH56yIly7HdcPgag8qtze8lrQ3ZzxgsrcM3NMEgGzvDKCiy23PNc1wuZG1WtUFsjrFF7yapzXmOJxO3JV7uCQ1tMoeow?testcase_id=4759801927303168 See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Mar 2 2017
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
|||||||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||||||
Comment 1 by sheriffbot@chromium.org
, Nov 22 2016