New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 708426 link

Starred by 1 user

Issue metadata

Status: Verified
Owner:
Closed: Apr 2017
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 1
Type: Bug



Sign in to add a comment

Out-of-memory in sfntly_fuzzer

Project Member Reported by ClusterFuzz, Apr 5 2017

Issue description

Cc: msrchandra@chromium.org
Labels: Test-Predator-Wrong M-59
Owner: thestig@chromium.org
Status: Assigned (was: Untriaged)
Predator and CL did not provide any possible suspects.
Using Code Search for the file, "sfntly_fuzzer" assigning to concern owner.
Suspecting Commit#
https://chromium.googlesource.com/chromium/src/+/05192643e8bfe9ece91d32bd6084f5ccfe33f5a4

@thestig -- Could you please take a look into the issue, kindly re-assign if this is not related to your changes.
Thank You.
Components: Internals>Skia>PDF
Status: Started (was: Assigned)
https://github.com/googlei18n/sfntly/pull/78
Project Member

Comment 4 by bugdroid1@chromium.org, Apr 14 2017

The following revision refers to this bug:
  https://chromium.googlesource.com/chromium/src.git/+/8fe3548c495a97473cd5490c33d52e5ff13925a1

commit 8fe3548c495a97473cd5490c33d52e5ff13925a1
Author: thestig <thestig@chromium.org>
Date: Fri Apr 14 04:46:31 2017

Roll DEPS for sfntly 04740d2..f033f85

f033f85 Merge pull request #78 from leizleiz/boundschecks
350164d ByteArray::Get() should not accept negative lengths.
4ca4ad0 Validate headers before constructing them.

BUG= 708426 , 711068 
TBR=behdad@chromium.org,jshin@chromium.org

Review-Url: https://codereview.chromium.org/2816153002
Cr-Commit-Position: refs/heads/master@{#464678}

[modify] https://crrev.com/8fe3548c495a97473cd5490c33d52e5ff13925a1/DEPS

Project Member

Comment 5 by ClusterFuzz, Apr 14 2017

Project Member

Comment 6 by ClusterFuzz, Apr 14 2017

Labels: ClusterFuzz-Verified
Status: Verified (was: Started)
ClusterFuzz testcase 4761071018835968 is verified as fixed, so closing issue.

If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.

Sign in to add a comment