Integer-overflow in CJBig2_TRDProc::decode_Arith |
||||
Issue descriptionDetailed report: https://clusterfuzz.com/testcase?key=6430198701752320 Fuzzer: ochang_search_index_mutator Job Type: linux_ubsan_chrome Platform Id: linux Crash Type: Integer-overflow Crash Address: Crash State: CJBig2_TRDProc::decode_Arith CJBig2_Context::parseTextRegion CJBig2_Context::parseSegmentData Sanitizer: undefined (UBSAN) Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_chrome&range=370022:370027 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=6430198701752320 Issue filed automatically. See https://github.com/google/clusterfuzz-tools for more information.
,
Oct 27 2017
Predator could not provide any possible suspects. Using the CL for the file, “ JBig2_TrdProc.cpp” assigning to concern owner for his recent work on this file. Suspect CL : https://pdfium.googlesource.com/pdfium.git/+/ebdba614b9683ddd1d50e8960639bc54c9d4bb7a npm@ -- Could you please look into this issue, kindly reassign if it has nothing to do with your changes. Thank You.
,
Oct 30 2017
The following revision refers to this bug: https://pdfium.googlesource.com/pdfium/+/956cb632e00558d20ccf756ebc286bce2674e774 commit 956cb632e00558d20ccf756ebc286bce2674e774 Author: Nicolas Pena <npm@chromium.org> Date: Mon Oct 30 19:30:52 2017 More safe ints in CJBig2_TRDProc Bug: chromium:778961 Change-Id: I1d08b3282304931276c24e50392c10b21780dcde Reviewed-on: https://pdfium-review.googlesource.com/16971 Commit-Queue: dsinclair <dsinclair@chromium.org> Reviewed-by: Tom Sepez <tsepez@chromium.org> Reviewed-by: dsinclair <dsinclair@chromium.org> [modify] https://crrev.com/956cb632e00558d20ccf756ebc286bce2674e774/core/fxcodec/jbig2/JBig2_TrdProc.cpp
,
Oct 31 2017
ClusterFuzz has detected this issue as fixed in range 512623:512673. Detailed report: https://clusterfuzz.com/testcase?key=6430198701752320 Fuzzer: ochang_search_index_mutator Job Type: linux_ubsan_chrome Platform Id: linux Crash Type: Integer-overflow Crash Address: Crash State: CJBig2_TRDProc::decode_Arith CJBig2_Context::parseTextRegion CJBig2_Context::parseSegmentData Sanitizer: undefined (UBSAN) Regressed: https://clusterfuzz.com/revisions?job=linux_ubsan_chrome&range=370022:370027 Fixed: https://clusterfuzz.com/revisions?job=linux_ubsan_chrome&range=512623:512673 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=6430198701752320 See https://github.com/google/clusterfuzz-tools for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Oct 31 2017
ClusterFuzz testcase 6430198701752320 is verified as fixed, so closing issue as verified. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
,
Nov 7 2017
|
||||
►
Sign in to add a comment |
||||
Comment 1 by ClusterFuzz
, Oct 27 2017Labels: Test-Predator-AutoComponents