Issue metadata
Sign in to add a comment
|
Crash in CPDF_HintTables::ReadPageHintTable |
||||||||||||||||||||||
Issue descriptionDetailed report: https://clusterfuzz.com/testcase?key=5140733614096384 Fuzzer: afl_pdf_hint_table_fuzzer Job Type: afl_chrome_asan Platform Id: linux Crash Type: UNKNOWN READ Crash Address: 0x00017fff7ffe Crash State: CPDF_HintTables::ReadPageHintTable HintTableForFuzzing::Fuzz Sanitizer: address (ASAN) Recommended Security Severity: Medium Regressed: https://clusterfuzz.com/revisions?job=afl_chrome_asan&range=514029:514033 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5140733614096384 Issue filed automatically. See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reference.md for more information.
,
Nov 4 2017
Automatically assigning owner based on suspected regression changelist https://pdfium.googlesource.com/pdfium/+/33591752d2cb14f2e07726ca52afce6efbdc07c9 (Simplify CPDF_HintsTable.). If this is incorrect, please remove the owner and apply the Test-Predator-Wrong-CLs label.
,
Nov 5 2017
,
Nov 5 2017
This is a serious security regression. If you are not able to fix this quickly, please revert the change that introduced it. If this doesn't affect a release branch, or has not been properly classified for severity, please update the Security_Impact or Security_Severity labels, and remove the ReleaseBlock label. To disable this altogether, apply ReleaseBlock-NA. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Nov 5 2017
,
Nov 6 2017
A revert has been submitted. https://pdfium-review.googlesource.com/c/pdfium/+/17830
,
Nov 6 2017
,
Nov 6 2017
This CL has been reverted, removing the RBS.
,
Nov 6 2017
Should we leave this open this the CL has been reverted? I commented on the revert CL as to what went wrong.
,
Nov 6 2017
I we should, when the CL is re-landed it should reference this BUG and we can close it then, yea? I removed the release block, so it's just a bug now.
,
Nov 7 2017
ClusterFuzz testcase 5313006765604864 is verified as fixed, so closing issue as verified. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
,
Nov 7 2017
I'm guessing the reverted CL will be re-landed. Keeping this open so we know it needs to be fixed with the reland.
,
Nov 7 2017
ClusterFuzz has detected this issue as fixed in range 514153:514189. Detailed report: https://clusterfuzz.com/testcase?key=5140733614096384 Fuzzer: afl_pdf_hint_table_fuzzer Job Type: afl_chrome_asan Platform Id: linux Crash Type: UNKNOWN READ Crash Address: 0x00017fff7ffe Crash State: CPDF_HintTables::ReadPageHintTable HintTableForFuzzing::Fuzz Sanitizer: address (ASAN) Recommended Security Severity: Medium Regressed: https://clusterfuzz.com/revisions?job=afl_chrome_asan&range=514029:514033 Fixed: https://clusterfuzz.com/revisions?job=afl_chrome_asan&range=514153:514189 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5140733614096384 See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reference.md for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Nov 7 2017
This is a serious security regression. If you are not able to fix this quickly, please revert the change that introduced it. If this doesn't affect a release branch, or has not been properly classified for severity, please update the Security_Impact or Security_Severity labels, and remove the ReleaseBlock label. To disable this altogether, apply ReleaseBlock-NA. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Nov 7 2017
This has been reverted so is not release block.
,
Nov 7 2017
,
Nov 7 2017
,
Nov 7 2017
,
Nov 7 2017
,
Nov 13 2017
The following revision refers to this bug: https://pdfium.googlesource.com/pdfium/+/cee39e6e90c219cc91f2c94a912a06977f4461a0 commit cee39e6e90c219cc91f2c94a912a06977f4461a0 Author: Lei Zhang <thestig@chromium.org> Date: Mon Nov 13 18:35:23 2017 Check first page number in IsLinearizedHeaderValid(). This should allow https://pdfium-review.googlesource.com/15770 to safely reland. BUG= chromium:781529 Change-Id: Id0c1bde3280fb72125d8e74751b9a1cb35302b6f Reviewed-on: https://pdfium-review.googlesource.com/18170 Reviewed-by: dsinclair <dsinclair@chromium.org> Commit-Queue: Lei Zhang <thestig@chromium.org> [modify] https://crrev.com/cee39e6e90c219cc91f2c94a912a06977f4461a0/core/fpdfapi/parser/cpdf_linearized_header.cpp
,
Nov 13 2017
The following revision refers to this bug: https://chromium.googlesource.com/chromium/src.git/+/fb9b79b4d71e2a05fe5fcf3f4f08574aa8b2cc28 commit fb9b79b4d71e2a05fe5fcf3f4f08574aa8b2cc28 Author: pdfium-deps-roller@chromium.org <pdfium-deps-roller@chromium.org> Date: Mon Nov 13 23:39:11 2017 Roll src/third_party/pdfium/ 9fa503624..f2d490650 (2 commits) https://pdfium.googlesource.com/pdfium.git/+log/9fa5036245c3..f2d490650cef $ git log 9fa503624..f2d490650 --date=short --no-merges --format='%ad %ae %s' 2017-11-13 hnakashima Remove virtual from EmbedderTest methods that are not overridden. 2017-11-13 thestig Check first page number in IsLinearizedHeaderValid(). Created with: roll-dep src/third_party/pdfium BUG= 781529 The AutoRoll server is located here: https://pdfium-roll.skia.org Documentation for the AutoRoller is here: https://skia.googlesource.com/buildbot/+/master/autoroll/README.md If the roll is causing failures, please contact the current sheriff, who should be CC'd on the roll, and stop the roller if necessary. TBR=dsinclair@chromium.org Change-Id: Ia254f6081520caf0c3eaa7cd6167c5ef6e52bdcc Reviewed-on: https://chromium-review.googlesource.com/767013 Reviewed-by: <pdfium-deps-roller@chromium.org> Commit-Queue: <pdfium-deps-roller@chromium.org> Cr-Commit-Position: refs/heads/master@{#516099} [modify] https://crrev.com/fb9b79b4d71e2a05fe5fcf3f4f08574aa8b2cc28/DEPS
,
Nov 19 2017
art-snake: Uh oh! This issue still open and hasn't been updated in the last 14 days. This is a serious vulnerability, and we want to ensure that there's progress. Could you please leave an update with the current status and any potential blockers? If you're not the right owner for this issue, could you please remove yourself as soon as possible or help us find the right one? If the issue is fixed or you can't reproduce it, please close the bug. If you've started working on a fix, please set the status to Started. Thanks for your time! To disable nags, add the Disable-Nags label. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Nov 21 2017
The fuzzer bug has been fixed. art-snake@ can revert the revert whenever.
,
Nov 22 2017
,
Feb 28 2018
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Mar 27 2018
|
|||||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||||
Comment 1 by ClusterFuzz
, Nov 4 2017Labels: Test-Predator-AutoComponents