Issue metadata
Sign in to add a comment
|
Bad-cast to CFX_DIBitmap from invalid vptr;XFACodecFuzzer::Fuzz;_start |
||||||||||||||||||||||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=5817620218773504 Fuzzer: libfuzzer_pdf_codec_bmp_fuzzer Job Type: libfuzzer_chrome_ubsan Platform Id: linux Crash Type: Bad-cast Crash Address: 0x00000a746670 Crash State: Bad-cast to CFX_DIBitmap from invalid vptr XFACodecFuzzer::Fuzz _start Recommended Security Severity: High Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_ubsan&range=434175:434379 Minimized Testcase (0.38 Kb): https://cluster-fuzz.appspot.com/download/AMIfv94fjaQssfDKGy5ajVn2i6_ybBdUKtdh3zPuNzA7-xO2JPg3qa13yRPLCItSpCnx7s6vleifOoY472i81cwl-FBHSmY20T57I8S5d8DQ5GRhEVFODEe22HfV2hZ6nVpky6_fL61VjxAfFiMCFpVZ1N9nHAgq6w?testcase_id=5817620218773504 Issue filed automatically. See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.
,
Dec 17 2016
This issue is a security regression. If you are not able to fix this quickly, please revert the change that introduced it. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Dec 17 2016
,
Dec 21 2016
dsinclair@, would you mind helping to find an owner?
,
Dec 21 2016
,
Dec 31 2016
dsinclair: Uh oh! This issue still open and hasn't been updated in the last 14 days. This is a serious vulnerability, and we want to ensure that there's progress. Could you please leave an update with the current status and any potential blockers? If you're not the right owner for this issue, could you please remove yourself as soon as possible or help us find the right one? If the issue is fixed or you can't reproduce it, please close the bug. If you've started working on a fix, please set the status to Started. Thanks for your time! To disable nags, add the Disable-Nags label. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Jan 2 2017
This is part of XFA which is disabled in all branches of Chrome.
,
Feb 28 2017
ClusterFuzz has detected this issue as fixed in range 453271:453317. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5817620218773504 Fuzzer: libfuzzer_pdf_codec_bmp_fuzzer Job Type: libfuzzer_chrome_ubsan Platform Id: linux Crash Type: Bad-cast Crash Address: 0x000009510680 Crash State: Bad-cast to CFX_DIBitmap from invalid vptr _start Sanitizer: undefined (UBSAN) Recommended Security Severity: High Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_ubsan&range=434175:434379 Fixed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_ubsan&range=453271:453317 Reproducer Testcase: https://cluster-fuzz.appspot.com/download/AMIfv966v_4Rj-8nCM8YZRxxMBiNIHVJPCbIhbUk85iEGhn6DoDtw_pG9mSj_FpfVUqg49Gz9Pxu4U0Vav1K5brq53p0PIJns8Aqh3f4IedFPVgugEhwAzEyIfe4oOMlP55xtuddsQFQcIGGzez9e7RkBwz8wmeoPBhxMZf9Rj4XayxD5TgpWo0vMeVwptd0SQShvSEymhtaEeykajCa2Es_MtrfMvMGF4hPmusPhcHzhlrR3rWsluLTfoQ4PVhRAqW03YGQn6MwbOjf10ICyILwsfGFZUUgc8Xq7hmzOgAbgSLOqK4pqpGsbp6M81TsTumtCem65dcXfldU5oR0XJO1ct3XUnmvJ6SWSJblWsMA5ZqR_8Bx3F4?testcase_id=5817620218773504 See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Feb 28 2017
https://pdfium.googlesource.com/pdfium/+/73c9f3bb3d82563d6d4496c4b0204d5c0825e8a2 "fixed" this.
,
Feb 28 2017
ClusterFuzz testcase 5817620218773504 is verified as fixed, so closing issue. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
,
Mar 1 2017
,
Jun 7 2017
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
|||||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||||
Comment 1 by sheriffbot@chromium.org
, Dec 17 2016