Issue metadata
Sign in to add a comment
|
Crash in CXFA_FMStringExpression::ToJavaScript |
||||||||||||||||||||||
Issue descriptionDetailed report: https://cluster-fuzz.appspot.com/testcase?key=5387233202012160 Fuzzer: afl_pdf_fm2js_fuzzer Job Type: afl_chrome_asan Platform Id: linux Crash Type: UNKNOWN READ Crash Address: 0x7f2b9a800000 Crash State: CXFA_FMStringExpression::ToJavaScript CXFA_FMExpExpression::ToImpliedReturnJS CXFA_FMFunctionDefinition::ToJavaScript Sanitizer: address (ASAN) Recommended Security Severity: High Regressed: https://cluster-fuzz.appspot.com/revisions?job=afl_chrome_asan&range=419709:419768 Reproducer Testcase: https://cluster-fuzz.appspot.com/download/AMIfv96lkSN6mtwM3Rdh1rkgIs-0wYgjVj_NCJeymI6d84EN8vGQQbtssqqOkpIX5ItFboGcv7GFpuTcm2n5AWyqoGalBT9VixwihC-kg3U0u2P74mtVE4RKZmKn-RKdEWquZzetfDVggbA5ncvU8Wp8YyiCotC8bC7mv5vyEuK4s5rTWvuQep6t8NgxAPXxxFTwXi6it8NkjQia5r1Cv_NnseYRuhxb31X1PHHS_ZPetbKAB1D6ds0wfzDlaB-L24AQK1SQ9A_a7KavYESoxdcJ9Oo2CtOwLRMtPjtEMrbfTCgwVZhnVbQEgjZ46PUn3Ip9_rvUcseI7Wh7b1M-Ux1Fw_Rnv4Hy0DB0wYVsJLBBxRZkIQuYudA?testcase_id=5387233202012160 Issue filed automatically. See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.
,
Mar 1 2017
,
Mar 1 2017
,
Mar 1 2017
XFA is not enabled on any branch of chrome.
,
Mar 2 2017
,
Apr 29 2017
ClusterFuzz has detected this issue as fixed in range 468180:468207. Detailed report: https://clusterfuzz.com/testcase?key=5387233202012160 Fuzzer: afl_pdf_fm2js_fuzzer Job Type: afl_chrome_asan Platform Id: linux Crash Type: UNKNOWN READ Crash Address: 0x7f2b9a800000 Crash State: CXFA_FMStringExpression::ToJavaScript CXFA_FMExpExpression::ToImpliedReturnJS CXFA_FMFunctionDefinition::ToJavaScript Sanitizer: address (ASAN) Recommended Security Severity: High Regressed: https://clusterfuzz.com/revisions?job=afl_chrome_asan&range=419709:419768 Fixed: https://clusterfuzz.com/revisions?job=afl_chrome_asan&range=468180:468207 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5387233202012160 See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Apr 29 2017
ClusterFuzz testcase 5387233202012160 is verified as fixed, so closing issue. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
,
Apr 30 2017
,
May 1 2017
I'm not sure if we did anything that would fixed this, we should verify.
,
May 2 2017
,
May 2 2017
Bulk-WontFixing these bugs. This was a bug on ClusterFuzz side, see bug 717534. We will start seeing new testcases auto-filed in a day or two. We can't leave these open as ClusterFuzz won't autoverify them after ClusterFuzz-Wrong label.
,
Aug 9 2017
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Sep 18 2017
We have made a bunch of changes on ClusterFuzz side, so resetting ClusterFuzz-Wrong label. |
|||||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||||
Comment 1 by sheriffbot@chromium.org
, Mar 1 2017