Issue metadata
Sign in to add a comment
|
Heap-buffer-overflow in ps_table_add |
||||||||||||||||||||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=6729545689595904 Fuzzer: attekett_surku_fuzzer Job Type: linux_asan_chrome_mp Platform Id: linux Crash Type: Heap-buffer-overflow READ 12 Crash Address: 0x61c0000017cf Crash State: ps_table_add parse_encoding parse_dict Sanitizer: address (ASAN) Recommended Security Severity: Medium Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_mp&range=314095:314100 Reproducer Testcase: https://cluster-fuzz.appspot.com/download/AMIfv97frKLbxzUyvlyy0ZUI44O2gKyvSWbEfidLS9WqTzswKdc7TBTb-EQ7uc-KqLSUvoCkC29epq9WQPoFhR3ckxhe7uo4e2YxvL0a-4otcD8sTedRlADnu_GJEJHvn9fJmjbQwcgoiQ6H4I9xUGscRm3jWk884M8L6fIbw02yy6IEEFMs3_i5F3frtSDFbeS4QNXiIGVtUNIQb5iKoTrDmCtsAppFvr2-pneRqLUPlG2HZVrFpI6UranI6Hne2yLAlwX0mxng9q0Lwe7WJzQzXsWMiN4LMw3mOEGIHiXMA7peE9grQlgGQh_54_ds57EjK7PFJx4BpaoYbDLzQmiIaDjV5radEOpsNETAza1UZdiIBAVY1a8?testcase_id=6729545689595904 Issue filed automatically. See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Mar 1 2017
ClusterFuzz has detected this issue as fixed in range 453200:453220. Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6729545689595904 Fuzzer: attekett_surku_fuzzer Job Type: linux_asan_chrome_mp Platform Id: linux Crash Type: Heap-buffer-overflow READ 12 Crash Address: 0x61c0000017cf Crash State: ps_table_add parse_encoding parse_dict Sanitizer: address (ASAN) Recommended Security Severity: Medium Regressed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_mp&range=314095:314100 Fixed: https://cluster-fuzz.appspot.com/revisions?job=linux_asan_chrome_mp&range=453200:453220 Reproducer Testcase: https://cluster-fuzz.appspot.com/download/AMIfv97frKLbxzUyvlyy0ZUI44O2gKyvSWbEfidLS9WqTzswKdc7TBTb-EQ7uc-KqLSUvoCkC29epq9WQPoFhR3ckxhe7uo4e2YxvL0a-4otcD8sTedRlADnu_GJEJHvn9fJmjbQwcgoiQ6H4I9xUGscRm3jWk884M8L6fIbw02yy6IEEFMs3_i5F3frtSDFbeS4QNXiIGVtUNIQb5iKoTrDmCtsAppFvr2-pneRqLUPlG2HZVrFpI6UranI6Hne2yLAlwX0mxng9q0Lwe7WJzQzXsWMiN4LMw3mOEGIHiXMA7peE9grQlgGQh_54_ds57EjK7PFJx4BpaoYbDLzQmiIaDjV5radEOpsNETAza1UZdiIBAVY1a8?testcase_id=6729545689595904 See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Mar 1 2017
ClusterFuzz testcase 6729545689595904 is verified as fixed, so closing issue. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
,
Mar 1 2017
,
Mar 5 2017
,
Mar 31 2017
,
Apr 1 2017
,
Apr 2 2017
Your change meets the bar and is auto-approved for M58. Please go ahead and merge the CL to branch 3029 manually. Please contact milestone owner if you have questions. Owners: amineer@(Android), cmasso@(iOS), bhthompson@(ChromeOS), govind@(Desktop) For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Apr 5 2017
This issue has been approved for a merge. Please merge the fix to any appropriate branches as soon as possible! If all merges have been completed, please remove any remaining Merge-Approved labels from this issue. Thanks for your time! To disable nags, add the Disable-Nags label. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Apr 5 2017
Nothing to merge here.
,
Apr 18 2017
,
Jun 7 2017
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Jul 28
|
|||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||
Comment 1 by ClusterFuzz
, Mar 1 2017