New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 683389 link

Starred by 1 user

Issue metadata

Status: Duplicate
Merged: issue 683211
Owner:
Last visit > 30 days ago
Closed: Jan 2017
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 1
Type: Bug-Security



Sign in to add a comment

Use-of-uninitialized-value in flac_read_header

Project Member Reported by ClusterFuzz, Jan 20 2017

Issue description

Project Member

Comment 1 by sheriffbot@chromium.org, Jan 21 2017

Labels: M-56
Project Member

Comment 2 by sheriffbot@chromium.org, Jan 21 2017

Labels: Pri-1

Comment 3 by est...@chromium.org, Jan 24 2017

Components: Internals>Media>FFmpeg
Owner: dalecur...@chromium.org
Status: Assigned (was: Untriaged)
dalecurtis, could you please help triage this? Thanks.
Cc: liber...@chromium.org
Owner: hubbe@chromium.org
Mergedinto: 683211
Status: Duplicate (was: Assigned)
this looks suspiciously like 683211, including the regression.  it's a flac header only (683211 is flac header + 1 byte), but it will have the same problem with avio_read.
Project Member

Comment 6 by ClusterFuzz, Jan 31 2017

ClusterFuzz has detected this issue as fixed in range 447059:447171.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6394102838198272

Fuzzer: libfuzzer_media_pipeline_integration_fuzzer
Job Type: libfuzzer_chrome_msan
Platform Id: linux

Crash Type: Use-of-uninitialized-value
Crash Address: 
Crash State:
  flac_read_header
  avformat_open_input
  media::FFmpegGlue::OpenContext
  
Sanitizer: memory (MSAN)

Recommended Security Severity: Medium

Regressed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_msan&range=413228:413328
Fixed: https://cluster-fuzz.appspot.com/revisions?job=libfuzzer_chrome_msan&range=447059:447171

Reproducer Testcase: https://cluster-fuzz.appspot.com/download/AMIfv961tUxUo8uUlzq5LTO2T2un2mqSxd1xKeS8v8W_xoUA0S9KQ009aXhDfrNk0ptTiJHkQgyf9LsZKDHzoZ2dui7lVJxKDr9kpR66OhDLOe9lRnhzFB5LrcW-5kF5MwF8Brv0dePnDnC3jDoBdxD2Wf8J1Zsk79a4aVg2UCrWL4i3FQqjiTgXf-56SWvQp5DdnSAYe_KyOgCj44xQEnaDkblSJzNsEXZhkPO0wiYf4mYZaoLdJVAxAGRBK6jePFAttnMXpb-OARHkgbzJ-eB4VNMFz-gvOTwuLogmQiMM-3w6xjFRKW5f5Vfj9mnj0R9m5fjCqXk_Jme03VyDpdodNcXN7StJHQl_oJpctXSXfpUUoV9GbSI?testcase_id=6394102838198272


See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 7 by sheriffbot@chromium.org, May 10 2017

Labels: -Restrict-View-SecurityTeam allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment