Issue metadata
Sign in to add a comment
|
Heap-buffer-overflow in puffin::BufferPuffReader::GetNext |
||||||||||||||||||||||
Issue descriptionDetailed report: https://clusterfuzz.com/testcase?key=6066852514758656 Fuzzer: libFuzzer_puffin_fuzzer Job Type: chromeos-test Platform Id: linux Crash Type: Heap-buffer-overflow READ 1 Crash Address: 0x60600000011e Crash State: puffin::BufferPuffReader::GetNext puffin::Huffer::HuffDeflate FuzzHuff Sanitizer: address (ASAN) Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=6066852514758656 Issue filed automatically. See https://github.com/google/clusterfuzz-tools for more information.
,
Mar 1 2018
,
Mar 1 2018
Another Puffer fuzzer hit.
,
Mar 1 2018
,
Mar 1 2018
,
Mar 1 2018
,
Mar 1 2018
,
Mar 1 2018
,
Mar 1 2018
,
Mar 2 2018
Detailed report: https://clusterfuzz.com/testcase?key=5678678303047680 Fuzzer: libFuzzer_puffin_fuzzer Job Type: libfuzzer_asan_chromeos Platform Id: linux Crash Type: Heap-buffer-overflow READ 1 Crash Address: 0x6020000000f3 Crash State: puffin::BufferPuffReader::GetNext puffin::Huffer::HuffDeflate fuzzer.cc Sanitizer: address (ASAN) Recommended Security Severity: Medium Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5678678303047680 See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reference.md for more information.
,
Mar 2 2018
Follow c#10 testcase, this uses the libfuzzer_asan_chromeos job type. chromeos-test job type is going away, so c#1 wont be verified. But c#10 will get verified. I have marked c#1 testcase as non-reproducible since chromeos-test job type will be removed soon.
,
Mar 2 2018
Sent this fix for review: https://android-review.googlesource.com/c/platform/external/puffin/+/631707
,
Mar 3 2018
,
Mar 5 2018
Fix is in, but also needs https://chromium-review.googlesource.com/c/chromiumos/overlays/chromiumos-overlay/%2B/946862
,
Mar 7 2018
Both CLs are landed now. Please, let us know what happens next!
,
Mar 16 2018
ClusterFuzz has detected this issue as fixed in range 231:234. Detailed report: https://clusterfuzz.com/testcase?key=5678678303047680 Fuzzer: libFuzzer_puffin_fuzzer Job Type: libfuzzer_asan_chromeos Platform Id: linux Crash Type: Heap-buffer-overflow READ 1 Crash Address: 0x6020000000f3 Crash State: puffin::BufferPuffReader::GetNext puffin::Huffer::HuffDeflate fuzzer.cc Sanitizer: address (ASAN) Recommended Security Severity: Medium Fixed: https://clusterfuzz.com/revisions?job=libfuzzer_asan_chromeos&range=231:234 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5678678303047680 See https://chromium.googlesource.com/chromium/src/+/master/testing/libfuzzer/reference.md for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
Mar 16 2018
,
Mar 17 2018
,
Mar 19 2018
,
Mar 19 2018
This bug requires manual review: M66 has already been promoted to the beta branch, so this requires manual review Please contact the milestone owner if you have questions. Owners: cmasso@(Android), cmasso@(iOS), josafat@(ChromeOS), abdulsyed@(Desktop) For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Mar 19 2018
Merge is not needed as Puffin was disabled in M65 and M66.
,
Jun 23 2018
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
,
Aug 13
|
|||||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||||
Comment 1 by sheriffbot@chromium.org
, Mar 1 2018