Integer-overflow in harfbuzz position_cluster |
|||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=4867996939190272 Fuzzer: inferno_twister Job Type: linux_ubsan_chrome Platform Id: linux Crash Type: Integer-overflow Crash Address: Crash State: position_cluster hb_ot_position hb_ot_shape_internal Sanitizer: undefined (UBSAN) Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_ubsan_chrome&range=434178:434216 Minimized Testcase (39.94 Kb): https://cluster-fuzz.appspot.com/download/AMIfv94AL5i1AWm63AMQ1ylt7SaMrenlojgMTmYSp-ReDuqviyobMvmbviK-CSPy-Ivtxb0PUOEZSR9LKkYrTjG8Sfnx51qopjpg3lY23soa-kJjQ_un4NlObH5f-7eyswMsE5bkXZs0LcOHuZU_pJeyl2md-eIVQ3_SgG0siLAz8mK7TFFNTO6EGxoCWGW4c9IphKvkvs-xor3euR0HpIXJuf3ONzbz_RPrh_4bbJCNBOhou_oCQlxIWciL-bbugWVWxELC5Dpz5dzI213phtw0R2QE0Xr6vGUS3EpHCHG3vaOyLUDIBnSYwrSBXLuV2JQ3eHD6Po2UfskgtpbzrtMcaZcB4DPeKh1UFju6iycP84FzgwrM2S0?testcase_id=4867996939190272 Issue filed automatically. See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Feb 1 2017
,
Feb 2 2017
,
May 11 2017
ClusterFuzz has detected this issue as fixed in range 470545:470729. Detailed report: https://clusterfuzz.com/testcase?key=4867996939190272 Fuzzer: inferno_twister Job Type: linux_ubsan_chrome Platform Id: linux Crash Type: Integer-overflow Crash Address: Crash State: position_cluster hb_ot_position hb_ot_shape_internal Sanitizer: undefined (UBSAN) Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_chrome&range=434178:434216 Fixed: https://clusterfuzz.com/revisions?job=linux_ubsan_chrome&range=470545:470729 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=4867996939190272 See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page. |
|||
►
Sign in to add a comment |
|||
Comment 1 by dtapu...@chromium.org
, Jan 30 2017Summary: Integer-overflow in harfbuzz position_cluster (was: Integer-overflow in position_cluster)