Issue metadata
Sign in to add a comment
|
Heap-buffer-overflow in SkiaState::ClipRestore |
||||||||||||||||||||
Issue descriptionDetailed report: https://clusterfuzz.com/testcase?key=4682468688134144 Fuzzer: libfuzzer_pdfium_fuzzer Job Type: libfuzzer_chrome_asan Platform Id: linux Crash Type: Heap-buffer-overflow READ 4 Crash Address: 0x604000051d5c Crash State: SkiaState::ClipRestore CFX_SkiaDeviceDriver::RestoreState CFX_RenderDevice::RestoreState Sanitizer: address (ASAN) Recommended Security Severity: Medium Regressed: https://clusterfuzz.com/revisions?job=libfuzzer_chrome_asan&range=458783:458809 Reproducer Testcase: https://clusterfuzz.com/download/AMIfv94G9j3xujTl0rtpBKbh0eRYEDub1afRHa3RLa4e6tI_wW5gfIoEmtvDoZO-7xVWoPSXYfxOGM5qtahee9aIMNidmIEj3IedgPxunMPwwKExGEJCpC7LkkxttOVQ6L8PY3y1EMfAn5ESokYNqElUI3CyDQEPGiaDesc85tabbxtpFg0DagkqLofFSFLeqcbs_P7tZLJ49BzX2LjAT4Jl6vKDtSSzDawOSRoz6-1blmn_QJewsEjIBgHKbKNtIUnDBaeBdBldAfe4UhiwnngUBjl7_2PT_soSuUFeUFKI2sfZSSnrs44t4lwXM7EA790cc5IBFl-pDn4BSVrozFvLGOh02vcBKBzpQecS-_YB9dJm_z_6S9N7hbZ7fgK_0UBackjawI8_x_ir_kUhJ0pLKV3WM-SVbw?testcase_id=4682468688134144 Issue filed automatically. See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.
,
Mar 24 2017
ClusterFuzz testcase 4682468688134144 is verified as fixed, so closing issue. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
,
Mar 24 2017
,
Jun 30 2017
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Jul 24 2017
,
Jul 28
|
|||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||
Comment 1 by ClusterFuzz
, Mar 24 2017