Issue metadata
Sign in to add a comment
|
Stack-buffer-overflow in CFX_SkiaDeviceDriver::DrawShading |
||||||||||||||||||||||
Issue descriptionDetailed report: https://clusterfuzz.com/testcase?key=5198453610381312 Fuzzer: lszekeres_pdf Job Type: linux_asan_pdfium Platform Id: linux Crash Type: Stack-buffer-overflow READ 4 Crash Address: 0x7ff1234a39e8 Crash State: CFX_SkiaDeviceDriver::DrawShading CPDF_RenderStatus::DrawShading CPDF_RenderStatus::ProcessShading Sanitizer: address (ASAN) Recommended Security Severity: Medium Regressed: https://clusterfuzz.com/revisions?job=linux_asan_pdfium&range=458746:458883 Reproducer Testcase: https://clusterfuzz.com/download/AMIfv94jEC_RE79OP7fXUafSVmQKU23IoSjOGbPcgcOb6BpyVhPx7aWxGWuaCk-ZT1DzEvNJ-plTre4pdRh-lDQMvgMKxA_T7dSKG9FjF0SnGPFRr6R7oRfPdIzWF-0NWAzMWx9Z1NDAtpk45A7PPYvRfOGGpGa9TDC9BmNC9Ud_w7hKfz_RzC0J_zEZh5k37RApP50UGs0IaIZW9RXatzZsKiGSkfVojCzMCKnGHghbcJpBlLbnOrRjAiKnEQfdcqrdN7w1Hzx_fxqsliWAYeght823adcP5GY2tdYujGOpsnTW6FIvWBVjk-h03BglKUgolqWh4sRZ3jo8-WkSSHOeLpaJD4-5vDQ0E_-flIe7IHWXVPEi53qqLoHsEF_N70MC5LhQTm5jObT3e1iHx2n67AWdxzffew?testcase_id=5198453610381312 Issue filed automatically. See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
,
Mar 23 2017
,
Mar 24 2017
,
Mar 24 2017
This issue is a security regression. If you are not able to fix this quickly, please revert the change that introduced it. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Mar 24 2017
,
Mar 29 2017
ClusterFuzz has detected this issue as fixed in range 460124:460171. Detailed report: https://clusterfuzz.com/testcase?key=5198453610381312 Fuzzer: lszekeres_pdf Job Type: linux_asan_pdfium Platform Id: linux Crash Type: Stack-buffer-overflow READ 4 Crash Address: 0x7ff1234a39e8 Crash State: CFX_SkiaDeviceDriver::DrawShading CPDF_RenderStatus::DrawShading CPDF_RenderStatus::ProcessShading Sanitizer: address (ASAN) Recommended Security Severity: Medium Regressed: https://clusterfuzz.com/revisions?job=linux_asan_pdfium&range=458746:458883 Fixed: https://clusterfuzz.com/revisions?job=linux_asan_pdfium&range=460124:460171 Reproducer Testcase: https://clusterfuzz.com/download/AMIfv94jEC_RE79OP7fXUafSVmQKU23IoSjOGbPcgcOb6BpyVhPx7aWxGWuaCk-ZT1DzEvNJ-plTre4pdRh-lDQMvgMKxA_T7dSKG9FjF0SnGPFRr6R7oRfPdIzWF-0NWAzMWx9Z1NDAtpk45A7PPYvRfOGGpGa9TDC9BmNC9Ud_w7hKfz_RzC0J_zEZh5k37RApP50UGs0IaIZW9RXatzZsKiGSkfVojCzMCKnGHghbcJpBlLbnOrRjAiKnEQfdcqrdN7w1Hzx_fxqsliWAYeght823adcP5GY2tdYujGOpsnTW6FIvWBVjk-h03BglKUgolqWh4sRZ3jo8-WkSSHOeLpaJD4-5vDQ0E_-flIe7IHWXVPEi53qqLoHsEF_N70MC5LhQTm5jObT3e1iHx2n67AWdxzffew?testcase_id=5198453610381312 See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Mar 29 2017
ClusterFuzz testcase 5198453610381312 is verified as fixed, so closing issue. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
,
Mar 29 2017
,
Mar 29 2017
The issue still exists even though skia paths was disabled on ToT.
,
Apr 17 2017
,
Jul 24 2017
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Sep 18 2017
We have made a bunch of changes on ClusterFuzz side, so resetting ClusterFuzz-Wrong label. |
|||||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||||
Comment 1 by rsesek@chromium.org
, Mar 23 2017Owner: dsinclair@chromium.org
Status: Assigned (was: Untriaged)