Heap-use-after-free in CCodec_ProgressiveDecoder::ReSampleScanline |
|||||||||||||
Issue descriptionDetailed report: https://clusterfuzz.com/testcase?key=5914723746054144 Fuzzer: libfuzzer_pdf_codec_gif_fuzzer Job Type: mac_libfuzzer_chrome_asan Platform Id: mac Crash Type: Heap-use-after-free READ 4 Crash Address: 0x602000008470 Crash State: CCodec_ProgressiveDecoder::ReSampleScanline CCodec_ProgressiveDecoder::GifReadScanline gif_load_frame Sanitizer: address (ASAN) Recommended Security Severity: High Regressed: https://clusterfuzz.com/revisions?job=mac_libfuzzer_chrome_asan&range=435670:435700 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5914723746054144 Issue filed automatically. See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information.
,
Apr 27 2017
,
Apr 27 2017
,
Apr 27 2017
,
Apr 27 2017
dsinclair: Can you please take a look? Thanks.
,
Apr 27 2017
XFA, not enabled on any branch of Chromium.
,
Apr 27 2017
,
May 2 2017
ClusterFuzz has detected this issue as fixed in range 468335:468354. Detailed report: https://clusterfuzz.com/testcase?key=5914723746054144 Fuzzer: libfuzzer_pdf_codec_gif_fuzzer Job Type: mac_libfuzzer_chrome_asan Platform Id: mac Crash Type: Heap-use-after-free READ 4 Crash Address: 0x602000008470 Crash State: CCodec_ProgressiveDecoder::ReSampleScanline CCodec_ProgressiveDecoder::GifReadScanline gif_load_frame Sanitizer: address (ASAN) Recommended Security Severity: High Regressed: https://clusterfuzz.com/revisions?job=mac_libfuzzer_chrome_asan&range=435670:435700 Fixed: https://clusterfuzz.com/revisions?job=mac_libfuzzer_chrome_asan&range=468335:468354 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5914723746054144 See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reproducing.md for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
May 2 2017
ClusterFuzz testcase 5914723746054144 is verified as fixed, so closing issue. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
,
May 2 2017
,
May 2 2017
We should verify if this is actually fixed.
,
May 2 2017
Bulk-WontFixing these bugs. This was a bug on ClusterFuzz side, see bug 717534. We will start seeing new testcases auto-filed in a day or two. We can't leave these open as ClusterFuzz won't autoverify them after ClusterFuzz-Wrong label.
,
Aug 9 2017
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Sep 18 2017
We have made a bunch of changes on ClusterFuzz side, so resetting ClusterFuzz-Wrong label. |
|||||||||||||
►
Sign in to add a comment |
|||||||||||||
Comment 1 by ClusterFuzz
, Apr 27 2017