Issue metadata
Sign in to add a comment
|
Use-after-poison in blink::HTMLFormElement::reset |
||||||||||||||||||||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=6730433544060928 Fuzzer: ifratric-browserfuzzer-v3 Job Type: mac_asan_chrome Platform Id: mac Crash Type: Use-after-poison READ 8 Crash Address: 0x7eaeb88a20b0 Crash State: blink::HTMLFormElement::reset blink::HTMLFormElementV8Internal::resetMethodCallback v8::internal::FunctionCallbackArguments::Call Recommended Security Severity: High Regressed: https://cluster-fuzz.appspot.com/revisions?job=mac_asan_chrome&range=437123:437180 Minimized Testcase (0.30 Kb): https://cluster-fuzz.appspot.com/download/AMIfv95dFVGmivvjGwQjCAwurpv0vUlxWW9P75y1i7BdGIeo0WtFX195-YJ-skjcxkWw5YZEY72vKt7pIxV7e9vOniahAEq90Gjn_tPXc1Bil9X7vz7xBWVUqALWhgMdCwJQ6H5iLMMTb7aJr2XHDTKaT2H1z0Dz2w?testcase_id=6730433544060928 Issue filed automatically. See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Dec 24 2016
ClusterFuzz testcase 6730433544060928 is verified as fixed, so closing issue. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
,
Dec 24 2016
,
Apr 1 2017
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Jul 28
|
|||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||
Comment 1 by ClusterFuzz
, Dec 24 2016