Issue metadata
Sign in to add a comment
|
Heap-buffer-overflow in ps_table_add |
||||||||||||||||||||||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=6143123739901952 Fuzzer: attekett_surku_fuzzer Job Type: linux_lsan_chrome_mp Platform Id: linux Crash Type: Heap-buffer-overflow READ 7 Crash Address: 0x61b000006890 Crash State: ps_table_add parse_encoding t1_load_keyword Sanitizer: address (ASAN) Recommended Security Severity: Medium Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_lsan_chrome_mp&range=314095:314100 Minimized Testcase (85.97 Kb): https://cluster-fuzz.appspot.com/download/AMIfv96KyH9GAOlcXydWdn9aOt40sV9gBfbpfwIWYQAlZmzDl-GwAxu-y9y12LRoIWvmP9uxNmkk1iGv6UqISw2qWAGUTrvOPKffLPW1CkA6J3FwuQUDumNA1PrA1W4tkOFA5P5QThPOuhP1ISa9zo5OODeyoieDj3Dx6YJOYDHRgj91GdJwnmKCpI2Llvp6W9SwM4EfHUpEbFhElS6bOzSCf4KpKTtRiiqI-iV-HJrYiYArNSwehSkTXzAcWeKKstdX94GlxvvYHXODoK1hQeBnKzLWnsND3B7TCiQUQ-LhQspPNhvLKIkoECE0FWHKGLdfk3Xr8pUFZcKkFcOcsOud_U4Vz1RMDSfxF4DijszKKFt8HKpzy_A?testcase_id=6143123739901952 Issue filed automatically. See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Jan 28 2017
I suspect this is a PDFium bug (based on the stack trace and the roll in the changelog). jam@, tsepez@?
,
Jan 29 2017
Assigning to tsepez for pdfium triage
,
Jan 29 2017
,
Jan 29 2017
,
Jan 30 2017
It looks like it's crashing in FreeType's Type 1 font code. FYI, I am working on linking latest FreeType statically in issue 274030 .
,
Feb 12 2017
tsepez: Uh oh! This issue still open and hasn't been updated in the last 14 days. This is a serious vulnerability, and we want to ensure that there's progress. Could you please leave an update with the current status and any potential blockers? If you're not the right owner for this issue, could you please remove yourself as soon as possible or help us find the right one? If the issue is fixed or you can't reproduce it, please close the bug. If you've started working on a fix, please set the status to Started. Thanks for your time! To disable nags, add the Disable-Nags label. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Feb 14 2017
I'm not working on this currently. To dan.
,
Feb 15 2017
I'm unable to repro this on my local build. How do I force chrome to use the bundled freetype2 when building?
,
Feb 28 2017
ClusterFuzz has detected this issue as fixed in range 453200:453220. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6143123739901952 Fuzzer: attekett_surku_fuzzer Job Type: linux_lsan_chrome_mp Platform Id: linux Crash Type: Heap-buffer-overflow READ 7 Crash Address: 0x61b000006890 Crash State: ps_table_add parse_encoding t1_load_keyword Sanitizer: address (ASAN) Recommended Security Severity: Medium Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_lsan_chrome_mp&range=314095:314100 Fixed: https://cluster-fuzz.appspot.com/revisions?job=linux_lsan_chrome_mp&range=453200:453220 Reproducer Testcase: https://cluster-fuzz.appspot.com/download/AMIfv96KyH9GAOlcXydWdn9aOt40sV9gBfbpfwIWYQAlZmzDl-GwAxu-y9y12LRoIWvmP9uxNmkk1iGv6UqISw2qWAGUTrvOPKffLPW1CkA6J3FwuQUDumNA1PrA1W4tkOFA5P5QThPOuhP1ISa9zo5OODeyoieDj3Dx6YJOYDHRgj91GdJwnmKCpI2Llvp6W9SwM4EfHUpEbFhElS6bOzSCf4KpKTtRiiqI-iV-HJrYiYArNSwehSkTXzAcWeKKstdX94GlxvvYHXODoK1hQeBnKzLWnsND3B7TCiQUQ-LhQspPNhvLKIkoECE0FWHKGLdfk3Xr8pUFZcKkFcOcsOud_U4Vz1RMDSfxF4DijszKKFt8HKpzy_A?testcase_id=6143123739901952 See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Feb 28 2017
The fixed changelog looks suspicious.
,
Feb 28 2017
ClusterFuzz testcase 6143123739901952 is verified as fixed, so closing issue. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
,
Feb 28 2017
Re #11, why? Most likely the FreeType update to 2.7.1 I did in https://chromium.googlesource.com/chromium/src/+/90d1657ffcf4eb720c60e572453477fad72377f9 fixed this issue.
,
Mar 1 2017
,
Mar 6 2017
,
Mar 13 2017
,
Mar 17 2017
,
Mar 18 2017
Your change meets the bar and is auto-approved for M58. Please go ahead and merge the CL to branch 3029 manually. Please contact milestone owner if you have questions. Owners: amineer@(Android), cmasso@(iOS), bhthompson@(ChromeOS), govind@(Desktop) For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Mar 20 2017
I don't think we want to merge the FreeType 2.7.1 update to M58. The FreeType we use for testing is not something we currently ship in the release version of the browser.
,
Mar 20 2017
Changing the owner to drott@ as it looks like their fix was the solution.
,
Mar 21 2017
This issue has been approved for a merge. Please merge the fix to any appropriate branches as soon as possible! If all merges have been completed, please remove any remaining Merge-Approved labels from this issue. Thanks for your time! To disable nags, add the Disable-Nags label. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Apr 4 2017
,
Apr 18 2017
,
Jun 7 2017
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
|||||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||||
Comment 1 by est...@chromium.org
, Jan 28 2017Components: Internals>Plugins>PDF
Owner: dpranke@chromium.org
Status: Assigned (was: Untriaged)