New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 738303 link

Starred by 1 user

Issue metadata

Status: Fixed
Owner:
Closed: Jul 2017
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Windows
Pri: 2
Type: Bug



Sign in to add a comment

Breakpoint in InvalidParameter

Project Member Reported by ClusterFuzz, Jun 30 2017

Issue description

Detailed report: https://clusterfuzz.com/testcase?key=6100592362782720

Fuzzer: attekett_surku_fuzzer
Job Type: windows_asan_chrome
Platform Id: windows

Crash Type: Breakpoint
Crash Address: 0xa8383880
Crash State:
  InvalidParameter
  _invalid_parameter
  _invalid_parameter_noinfo
  
Sanitizer: address (ASAN)

Regressed: https://clusterfuzz.com/revisions?job=windows_asan_chrome&range=479886:479938

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=6100592362782720


Issue filed automatically.

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 
Cc: msrchandra@chromium.org
Components: Internals>Skia>PDF
Labels: M-61 Test-Predator-Correct-CLs
Owner: thestig@chromium.org
Status: Assigned (was: Untriaged)
Assigning to concern owner from Predator results --
Regression information is not available. The result is the blame information

Author: pmonette
Project: chromium
Changelist: https://chromium.googlesource.com/chromium/src/+/18d3ed36f113ef9fb159d729ec5c89b578ece692
Time: Fri Oct 16 21:06:06 2015
The CL last changed line 20 of file process_startup_helper.cc, which is stack frame 0. 

Author: Lei Zhang
Project: chromium-pdfium
Changelist: https://pdfium.googlesource.com/pdfium.git/+/2bf942d8c21b653efdfdcae681769cffbfaa0663
Time: Fri Jun 16 13:48:19 2017 -0700
The CL last changed line 298 of file util.cpp, which is stack frame 6.

@thestig -- Could you please look into the issue, kindly re-assign if this is not related to your changes.
Thank You

Components: -Internals>Skia>PDF Internals>Plugins>PDF
Labels: -Pri-1 Pri-2
Status: Started (was: Assigned)
https://pdfium-review.googlesource.com/8210
Project Member

Comment 4 by bugdroid1@chromium.org, Jul 19 2017

The following revision refers to this bug:
  https://pdfium.googlesource.com/pdfium/+/d0f1054087094e5c353aead6bc3370635b69b278

commit d0f1054087094e5c353aead6bc3370635b69b278
Author: Lei Zhang <thestig@chromium.org>
Date: Wed Jul 19 13:19:10 2017

Prevent more crashes in wcsftime.

BUG= chromium:738303 

Change-Id: If36cdc0f53fc224c0c4c8cf775fd2c916f2d0add
Reviewed-on: https://pdfium-review.googlesource.com/8210
Commit-Queue: dsinclair <dsinclair@chromium.org>
Reviewed-by: dsinclair <dsinclair@chromium.org>

[modify] https://crrev.com/d0f1054087094e5c353aead6bc3370635b69b278/core/fxcrt/fx_system.cpp
[modify] https://crrev.com/d0f1054087094e5c353aead6bc3370635b69b278/core/fxcrt/fx_system_unittest.cpp

Project Member

Comment 5 by bugdroid1@chromium.org, Jul 19 2017

The following revision refers to this bug:
  https://chromium.googlesource.com/chromium/src.git/+/5d855a7483a74d76fa6a6f02ba222c768cfdab53

commit 5d855a7483a74d76fa6a6f02ba222c768cfdab53
Author: pdfium-deps-roller@chromium.org <pdfium-deps-roller@chromium.org>
Date: Wed Jul 19 15:57:37 2017

Roll src/third_party/pdfium/ 19817af6f..23c93ef6e (2 commits)

https://pdfium.googlesource.com/pdfium.git/+log/19817af6f201..23c93ef6e3b9

$ git log 19817af6f..23c93ef6e --date=short --no-merges --format='%ad %ae %s'
2017-07-18 tsepez Avoid unterminated string segment in cfx_saxreaderhandler.cpp
2017-07-18 thestig Prevent more crashes in wcsftime.

Created with:
  roll-dep src/third_party/pdfium
BUG= 738303 


Documentation for the AutoRoller is here:
https://skia.googlesource.com/buildbot/+/master/autoroll/README.md

If the roll is causing failures, see:
http://www.chromium.org/developers/tree-sheriffs/sheriff-details-chromium#TOC-Failures-due-to-DEPS-rolls


TBR=dsinclair@chromium.org

Change-Id: I32dd5ef3587cbe13fe9dc877dca240b51c12e8be
Reviewed-on: https://chromium-review.googlesource.com/577633
Reviewed-by: <pdfium-deps-roller@chromium.org>
Commit-Queue: <pdfium-deps-roller@chromium.org>
Cr-Commit-Position: refs/heads/master@{#487878}
[modify] https://crrev.com/5d855a7483a74d76fa6a6f02ba222c768cfdab53/DEPS

Status: Fixed (was: Started)
Project Member

Comment 7 by ClusterFuzz, Jul 20 2017

ClusterFuzz has detected this issue as fixed in range 487872:487903.

Detailed report: https://clusterfuzz.com/testcase?key=6100592362782720

Fuzzer: attekett_surku_fuzzer
Job Type: windows_asan_chrome
Platform Id: windows

Crash Type: Breakpoint
Crash Address: 0xa8383880
Crash State:
  InvalidParameter
  _invalid_parameter
  _invalid_parameter_noinfo
  
Sanitizer: address (ASAN)

Regressed: https://clusterfuzz.com/revisions?job=windows_asan_chrome&range=479886:479938
Fixed: https://clusterfuzz.com/revisions?job=windows_asan_chrome&range=487872:487903

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=6100592362782720


See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.

Sign in to add a comment