Issue metadata
Sign in to add a comment
|
Heap-double-free in CPDF_StreamParser::ReadInlineStream |
||||||||||||||||||||||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=5543694972485632 Fuzzer: ifratric_pdf_generic Job Type: linux_asan_pdfium Platform Id: linux Crash Type: Heap-double-free Crash Address: 0x610000000540 Crash State: CPDF_StreamParser::ReadInlineStream CPDF_StreamContentParser::Handle_BeginImage CPDF_StreamContentParser::Parse Recommended Security Severity: High Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_pdfium&range=438853:439220 Minimized Testcase (5613.75 Kb): https://cluster-fuzz.appspot.com/download/AMIfv964f0M-0Mvt3udpd22j4atgsyHM448GSSzYkB97As4BX5o6l3agPFA25bACrNhmUMBGGTYhwbQahGBZ5o-Dg07arRDHsLX7NNVKbeyysR6ix40zETMAh4H1yRyT8Xt-KxWA7FFgsx_Mq9I5LXtldug7CrRqLblVUp3p5uJls_pxgwQ1pYg?testcase_id=5543694972485632 Issue filed automatically. See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Dec 17 2016
This issue is a security regression. If you are not able to fix this quickly, please revert the change that introduced it. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Dec 17 2016
,
Dec 20 2016
dsinclair: Could you please take a look or help us find an owner for this?
,
Dec 20 2016
,
Dec 20 2016
Issue 675323 has been merged into this issue.
,
Dec 20 2016
ClusterFuzz has detected this issue as fixed in range 439611:439688. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5543694972485632 Fuzzer: ifratric_pdf_generic Job Type: linux_asan_pdfium Platform Id: linux Crash Type: Heap-double-free Crash Address: 0x610000000540 Crash State: CPDF_StreamParser::ReadInlineStream CPDF_StreamContentParser::Handle_BeginImage CPDF_StreamContentParser::Parse Recommended Security Severity: High Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_pdfium&range=438853:439220 Fixed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_pdfium&range=439611:439688 Minimized Testcase (5613.75 Kb): https://cluster-fuzz.appspot.com/download/AMIfv964f0M-0Mvt3udpd22j4atgsyHM448GSSzYkB97As4BX5o6l3agPFA25bACrNhmUMBGGTYhwbQahGBZ5o-Dg07arRDHsLX7NNVKbeyysR6ix40zETMAh4H1yRyT8Xt-KxWA7FFgsx_Mq9I5LXtldug7CrRqLblVUp3p5uJls_pxgwQ1pYg?testcase_id=5543694972485632 See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Dec 20 2016
ClusterFuzz testcase 4957153569013760 is verified as fixed, so closing issue. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
,
Dec 20 2016
,
Jan 27 2017
,
Mar 28 2017
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
May 15 2017
|
|||||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||||
Comment 1 by sheriffbot@chromium.org
, Dec 17 2016