New issue
Advanced search Search tips

Issue 713175 link

Starred by 1 user

Issue metadata

Status: Verified
Owner: ----
Closed: Apr 2017
Cc:
EstimatedDays: ----
NextAction: ----
OS: Windows
Pri: 1
Type: Bug-Security



Sign in to add a comment

Stack-buffer-overflow in IntersectSides

Project Member Reported by ClusterFuzz, Apr 19 2017

Issue description

Detailed report: https://clusterfuzz.com/testcase?key=5870525261021184

Fuzzer: ifratric_pdf_generic
Job Type: windows_asan_chrome_no_sandbox
Platform Id: windows

Crash Type: Stack-buffer-overflow READ 4
Crash Address: 0x049fb2bc
Crash State:
  IntersectSides
  CFX_SkiaDeviceDriver::DrawShading
  CPDF_RenderStatus::DrawShading
  
Sanitizer: address (ASAN)

Recommended Security Severity: Medium

Reproducer Testcase: https://clusterfuzz.com/download/AMIfv94gBWqc_ljss-gF_rUNUoqtlCrB0yj9ADWEjhzQruPYlv7wbD_4DL0B7zU64TQv7N0-8jAWyFgNjH9ysrdVpxDJu74aFyRhsZbLsCi3tuYHrs0WMKK4VfeoPcEtQFLi6ynl7q8tzQO_o1Uxt_ZZsvJWq0xgRMUhy8O_PYfXz91k2fzb8ehdIBgDYqPhoXufRuIxg-UqLCp0H32VavLdLuxzEEQFMfgEDrOE4PMIUGZX7a-q6s2Ot2C1aahRqaO5n99cEnShr8BSC0rDQNSbai76jY_0doiKeZeYaqTOfvsqz8FkrOXekDGU0VivJA9VXXZoKKB6Ce3gO8n6B0PcjEcgpqCJ50GRWOW4C5lX2N0jdlxALJy9vzplDfQch7AKfgY-6C6mvGgW6L2ag1ZxEAAMXTPIhw?testcase_id=5870525261021184


Issue filed automatically.

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 
Project Member

Comment 1 by ClusterFuzz, Apr 19 2017

ClusterFuzz has detected this issue as fixed in range 460139:460163.

Detailed report: https://clusterfuzz.com/testcase?key=5870525261021184

Fuzzer: ifratric_pdf_generic
Job Type: windows_asan_chrome_no_sandbox
Platform Id: windows

Crash Type: Stack-buffer-overflow READ 4
Crash Address: 0x049fb2bc
Crash State:
  IntersectSides
  CFX_SkiaDeviceDriver::DrawShading
  CPDF_RenderStatus::DrawShading
  
Sanitizer: address (ASAN)

Recommended Security Severity: Medium

Fixed: https://clusterfuzz.com/revisions?job=windows_asan_chrome_no_sandbox&range=460139:460163

Reproducer Testcase: https://clusterfuzz.com/download/AMIfv94gBWqc_ljss-gF_rUNUoqtlCrB0yj9ADWEjhzQruPYlv7wbD_4DL0B7zU64TQv7N0-8jAWyFgNjH9ysrdVpxDJu74aFyRhsZbLsCi3tuYHrs0WMKK4VfeoPcEtQFLi6ynl7q8tzQO_o1Uxt_ZZsvJWq0xgRMUhy8O_PYfXz91k2fzb8ehdIBgDYqPhoXufRuIxg-UqLCp0H32VavLdLuxzEEQFMfgEDrOE4PMIUGZX7a-q6s2Ot2C1aahRqaO5n99cEnShr8BSC0rDQNSbai76jY_0doiKeZeYaqTOfvsqz8FkrOXekDGU0VivJA9VXXZoKKB6Ce3gO8n6B0PcjEcgpqCJ50GRWOW4C5lX2N0jdlxALJy9vzplDfQch7AKfgY-6C6mvGgW6L2ag1ZxEAAMXTPIhw?testcase_id=5870525261021184


See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 2 by ClusterFuzz, Apr 19 2017

Labels: ClusterFuzz-Verified
Status: Verified (was: Untriaged)
ClusterFuzz testcase 5870525261021184 is verified as fixed, so closing issue.

If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
Project Member

Comment 3 by sheriffbot@chromium.org, Apr 20 2017

Labels: -Restrict-View-SecurityTeam Restrict-View-SecurityNotify
Labels: M-59
Labels: Release-0-M59
Project Member

Comment 6 by sheriffbot@chromium.org, Jul 27 2017

Labels: -Restrict-View-SecurityNotify allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 7 by sheriffbot@chromium.org, Jul 28

Labels: Pri-1

Sign in to add a comment