New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 688217 link

Starred by 1 user

Issue metadata

Status: Duplicate
Owner:
OOO till Sep 3rd
Closed: Feb 2017
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 2
Type: Bug



Sign in to add a comment

Integer-overflow in blink::HTMLElement::attributeChanged

Project Member Reported by ClusterFuzz, Feb 3 2017

Issue description

Components: Blink>Editing>Spellcheck
Labels: M-58 Test-Predator-Wrong
Owner: r...@chromium.org
Status: Assigned (was: Untriaged)
As per issue 687984, assigning to rego@. could you please take a look?
Thank you.

Comment 2 by r...@chromium.org, Feb 3 2017

Mergedinto: 687984
Status: Duplicate (was: Assigned)
Project Member

Comment 3 by ClusterFuzz, Feb 4 2017

ClusterFuzz has detected this issue as fixed in range 447975:447979.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5280735075500032

Fuzzer: ifratric-browserfuzzer-v3
Job Type: linux_ubsan_chrome
Platform Id: linux

Crash Type: Integer-overflow
Crash Address: 
Crash State:
  blink::HTMLElement::attributeChanged
  blink::Element::didAddAttribute
  blink::Element::appendAttributeInternal
  
Sanitizer: undefined (UBSAN)

Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_ubsan_chrome&range=447722:447732
Fixed: https://cluster-fuzz.appspot.com/revisions?job=linux_ubsan_chrome&range=447975:447979

Reproducer Testcase: https://cluster-fuzz.appspot.com/download/AMIfv977kl3kfI0U18HKFQJZideNfkP6cPIBHo6mH6xunjYpyzGX5YzTyh8nvcGg2lrCCuVpWg1e8xn2ukqMyIx96Cnvfv6fJa83KIRznRjkXdurE6fW_Xf364u63YUdXXM93-R47pj92Z7tnyKW-my6Zdyry43h2NTU_N_dZ6cP12wpZFe9y7hfMTDd4k_T-QVuxZcYo_Mw-8uKgtWSgrv09VssjF1tybjO65m4DhvJv-oMkEnTVczTap7v_89O1KClv3WNhcHIIKAjHOq3P5twCWV65j8CXW86F7SkF7SzmE0S7Wik90zXO9MtEJt5W7hhrohqvKgv6e2kFp2WawtdHU0XX5_QOJKb_jb7Djm87jE-w-8D70OKvdXTcXBYbO5tPkteU27TsTM9ukiW_J4XJnx6rlxOFQ?testcase_id=5280735075500032


See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.

Sign in to add a comment