Integer-overflow in blink::Element::synchronizeAttribute |
||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=6382738828689408 Fuzzer: ifratric-browserfuzzer-v3 Job Type: linux_ubsan_chrome Platform Id: linux Crash Type: Integer-overflow Crash Address: Crash State: blink::Element::synchronizeAttribute blink::Element::setAttribute blink::Element::setIntegralAttribute Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_ubsan_chrome&range=434043:434111 Minimized Testcase (0.70 Kb): https://cluster-fuzz.appspot.com/download/AMIfv94qZ6_NXfjWe3DNSbhAV2EFYRv_tMkhlNco-LcRB0QkYNBfLP5rGoZfynjmJlpRgCco_c9-yZB9jPrRS-lSox_VyItYIOch1QhdzpEdvx2-KyVgwmpFEDbPs4I1dfC16JcbnkWhb3sOKkCKJtA9E-w2AuCekQ?testcase_id=6382738828689408 Issue filed automatically. See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Nov 28 2016
ClusterFuzz testcase is verified as fixed, closing issue. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue. |
||
►
Sign in to add a comment |
||
Comment 1 by ClusterFuzz
, Nov 28 2016