Integer-overflow in Buffer_itoa |
||||||||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=6711728286203904 Fuzzer: libfuzzer_pdfium_fuzzer Job Type: libfuzzer_chrome_ubsan Platform Id: linux Crash Type: Integer-overflow Crash Address: Crash State: Buffer_itoa CFX_ByteString::FormatInteger CPDF_Number::GetString Sanitizer: undefined (UBSAN) Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_ubsan&range=408371:408428 Minimized Testcase (0.36 Kb): https://cluster-fuzz.appspot.com/download/AMIfv94qHA-VZlG7OZ3-tMYUf1Pm7RSxtJ8fpzMgWvfC7RsrCQDB-vkHbY84IG9AYHjDRH4FVxpZdos_2wE55Rzk4Zu4IcIw7BFH3Kg6uvFqi__HSbWBABI8M-7NHHfvSBQQqU614K6veZPi0w9S8fjnyRjrrOG_iEmAphKGFGDMDI_6vXO4JStAq-6KOOXDz9lFXQg7I1_WrmoFJeTpyTp4SvKOlOz7DgO2bdm9tJMQihiYowz3eqE4vjRY7IvfrWDRJUjenDSdCn894BMOLDDdNijs54ocI9Iyd7Zh4x5xNXmYm2BYn3_4e-mO98mAflTT_xBp6J4pU6dAiw0YFkb1N405g7VMRrbLaNkt0j3Za9yqYROZHD0?testcase_id=6711728286203904 Issue filed automatically. See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.
,
Feb 7 2017
,
Jul 30 2017
Detailed report: https://clusterfuzz.com/testcase?key=5575141651382272 Fuzzer: pdfium_fuzzer Job Type: libfuzzer_chrome_ubsan Crash Type: Integer-overflow Crash Address: Crash State: Buffer_itoa CFX_ByteString::FormatInteger CPDF_Number::GetString Sanitizer: undefined (UBSAN) Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5575141651382272 See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.
,
Jul 31 2017
Detailed report: https://clusterfuzz.com/testcase?key=5575141651382272 Fuzzer: pdfium_fuzzer Job Type: libfuzzer_chrome_ubsan Crash Type: Integer-overflow Crash Address: Crash State: Buffer_itoa CFX_ByteString::FormatInteger CPDF_Number::GetString Sanitizer: undefined (UBSAN) Regressed: https://clusterfuzz.com/revisions?job=libfuzzer_chrome_ubsan&range=423338:423416 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5575141651382272 See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.
,
Aug 29 2017
ClusterFuzz has detected this issue as fixed in range 497785:497822. Detailed report: https://clusterfuzz.com/testcase?key=5575141651382272 Fuzzer: pdfium_fuzzer Job Type: libfuzzer_chrome_ubsan Crash Type: Integer-overflow Crash Address: Crash State: Buffer_itoa CFX_ByteString::FormatInteger CPDF_Number::GetString Sanitizer: undefined (UBSAN) Regressed: https://clusterfuzz.com/revisions?job=libfuzzer_chrome_ubsan&range=423338:423416 Fixed: https://clusterfuzz.com/revisions?job=libfuzzer_chrome_ubsan&range=497785:497822 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5575141651382272 See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Aug 29 2017
ClusterFuzz testcase 5575141651382272 is verified as fixed, so closing issue as verified. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
,
Aug 29 2017
I suspect CF might be wrong, at least about the fixed CL range. We should double check.
,
Aug 31 2017
,
Sep 1 2017
,
Sep 1 2017
Clusterfuzz was right, this CL fixed the issue on this test case: https://pdfium-review.googlesource.com/c/pdfium/+/10511
,
Sep 1 2017
|
||||||||
►
Sign in to add a comment |
||||||||
Comment 1 by mummare...@chromium.org
, Jan 18 2017Components: Internals>Plugins>PDF
Labels: Test-Predator-Wrong M-56