Issue metadata
Sign in to add a comment
|
Global-buffer-overflow in puffin::Huffer::HuffDeflate |
||||||||||||||||||||||
Issue descriptionDetailed report: https://clusterfuzz.com/testcase?key=5831168432537600 Fuzzer: libFuzzer_puffin_fuzzer Job Type: chromeos-test Platform Id: linux Crash Type: Global-buffer-overflow READ 1 Crash Address: 0x55f9b3a5ce7f Crash State: puffin::Huffer::HuffDeflate FuzzHuff fuzzer.cc Sanitizer: address (ASAN) Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5831168432537600 Issue filed automatically. See https://github.com/google/clusterfuzz-tools for more information.
,
Mar 1 2018
,
Mar 1 2018
ahassani@: The Puffin fuzzer has found a couple of issues, can you please take a look? Also, what is the security exposure of this code, for the sake of setting severity?
,
Mar 1 2018
,
Mar 1 2018
,
Mar 1 2018
,
Mar 1 2018
,
Mar 1 2018
,
Mar 1 2018
,
Mar 2 2018
,
Mar 2 2018
Detailed report: https://clusterfuzz.com/testcase?key=5293113619513344 Fuzzer: libFuzzer_puffin_fuzzer Job Type: libfuzzer_asan_chromeos Platform Id: linux Crash Type: Global-buffer-overflow READ 1 Crash Address: 0x55b644a97e9e Crash State: puffin::Huffer::HuffDeflate fuzzer.cc Sanitizer: address (ASAN) Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5293113619513344 See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reference.md for more information.
,
Mar 2 2018
USe c#11 testcase with libfuzzer_asan_chromeos job type. Ignore c#1 testcase, that is with chromeos-test job type which is going away.
,
Mar 2 2018
Sent this fix for review: https://android-review.googlesource.com/c/platform/external/puffin/+/631707
,
Mar 3 2018
,
Mar 3 2018
,
Mar 5 2018
Fix is in, but also needs https://chromium-review.googlesource.com/c/chromiumos/overlays/chromiumos-overlay/%2B/946862
,
Mar 16 2018
ahassani: Uh oh! This issue still open and hasn't been updated in the last 14 days. This is a serious vulnerability, and we want to ensure that there's progress. Could you please leave an update with the current status and any potential blockers? If you're not the right owner for this issue, could you please remove yourself as soon as possible or help us find the right one? If the issue is fixed or you can't reproduce it, please close the bug. If you've started working on a fix, please set the status to Started. Thanks for your time! To disable nags, add the Disable-Nags label. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Mar 16 2018
@manojgupta: I thought it will be marked as fixed once the root cause is resolve (which in this case it is). Should I manually fix it?
,
Mar 16 2018
Regarding #18, inferno@ should know the answer for this.
,
Mar 16 2018
ClusterFuzz has detected this issue as fixed in range 231:234. Detailed report: https://clusterfuzz.com/testcase?key=5293113619513344 Fuzzer: libFuzzer_puffin_fuzzer Job Type: libfuzzer_asan_chromeos Platform Id: linux Crash Type: Global-buffer-overflow READ 1 Crash Address: 0x55b644a97e9e Crash State: puffin::Huffer::HuffDeflate fuzzer.cc Sanitizer: address (ASAN) Fixed: https://clusterfuzz.com/revisions?job=libfuzzer_asan_chromeos&range=231:234 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5293113619513344 See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reference.md for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Mar 16 2018
,
Mar 17 2018
,
Mar 19 2018
,
Mar 19 2018
This bug requires manual review: M66 has already been promoted to the beta branch, so this requires manual review Please contact the milestone owner if you have questions. Owners: cmasso@(Android), cmasso@(iOS), josafat@(ChromeOS), abdulsyed@(Desktop) For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Mar 19 2018
Merge is not needed as Puffin was disabled in M65 and M66.
,
Jun 23 2018
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Aug 13
|
|||||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||||
Comment 1 by sheriffbot@chromium.org
, Mar 1 2018