Issue metadata
Sign in to add a comment
|
Heap-use-after-free in CJBig2_Image::~CJBig2_Image |
||||||||||||||||||||||
Issue descriptionDetailed report: https://clusterfuzz.com/testcase?key=5201753398837248 Fuzzer: ifratric_pdf_generic Job Type: windows_asan_chrome_no_sandbox Platform Id: windows Crash Type: Heap-use-after-free READ 1 Crash Address: 0x123967171800 Crash State: CJBig2_Image::~CJBig2_Image CJBig2_Context::~CJBig2_Context CCodec_Jbig2Context::~CCodec_Jbig2Context Sanitizer: address (ASAN) Recommended Security Severity: Medium Regressed: https://clusterfuzz.com/revisions?job=windows_asan_chrome_no_sandbox&range=533127:533139 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5201753398837248 Additional requirements: Requires Gestures Issue filed automatically. See https://github.com/google/clusterfuzz-tools for more information.
,
May 8 2018
Automatically applying components based on crash stacktrace and information from OWNERS files. If this is incorrect, please apply the Test-Predator-Wrong-Components label.
,
May 8 2018
,
May 8 2018
,
May 9 2018
Another stale pointer warning, not a blocker.
,
May 9 2018
CL pending at https://pdfium-review.googlesource.com/c/pdfium/+/32311
,
May 10 2018
,
May 10 2018
The following revision refers to this bug: https://chromium.googlesource.com/chromium/src.git/+/511f71f2d113829989df1949d1a9343f1d0019f8 commit 511f71f2d113829989df1949d1a9343f1d0019f8 Author: pdfium-chromium-autoroll@skia-buildbots.google.com.iam.gserviceaccount.com <pdfium-chromium-autoroll@skia-buildbots.google.com.iam.gserviceaccount.com> Date: Thu May 10 20:13:17 2018 Roll src/third_party/pdfium/ 95061379c..80302c77a (5 commits) https://pdfium.googlesource.com/pdfium.git/+log/95061379c945..80302c77a854 $ git log 95061379c..80302c77a --date=short --no-merges --format='%ad %ae %s' 2018-05-10 rharrison Use test_dir instead of 'pdfium' for source type 2018-05-10 thestig Add CPDF_Transparency. 2018-05-10 thestig Make GetTestDataDir() work in a non-standalone checkout. 2018-05-10 tsepez Fix destruction order in CPDF_Dibsource. 2018-05-10 npm Remove a completeness check from CJBig2_GRRDProc::DecodeTemplate0Opt Created with: roll-dep src/third_party/pdfium BUG= chromium:841513 , chromium:840695 , chromium:841200 The AutoRoll server is located here: https://pdfium-roll.skia.org Documentation for the AutoRoller is here: https://skia.googlesource.com/buildbot/+/master/autoroll/README.md If the roll is causing failures, please contact the current sheriff, who should be CC'd on the roll, and stop the roller if necessary. TBR=dsinclair@chromium.org Change-Id: I579c4a7663af521bb842f5e0f309f2bcd71732f3 Reviewed-on: https://chromium-review.googlesource.com/1054263 Reviewed-by: pdfium-chromium-autoroll <pdfium-chromium-autoroll@skia-buildbots.google.com.iam.gserviceaccount.com> Commit-Queue: pdfium-chromium-autoroll <pdfium-chromium-autoroll@skia-buildbots.google.com.iam.gserviceaccount.com> Cr-Commit-Position: refs/heads/master@{#557647} [modify] https://crrev.com/511f71f2d113829989df1949d1a9343f1d0019f8/DEPS
,
May 15 2018
ClusterFuzz has detected this issue as fixed in range 557631:558316. Detailed report: https://clusterfuzz.com/testcase?key=5201753398837248 Fuzzer: ifratric_pdf_generic Job Type: windows_asan_chrome_no_sandbox Platform Id: windows Crash Type: Heap-use-after-free READ 1 Crash Address: 0x123967171800 Crash State: CJBig2_Image::~CJBig2_Image CJBig2_Context::~CJBig2_Context CCodec_Jbig2Context::~CCodec_Jbig2Context Sanitizer: address (ASAN) Recommended Security Severity: Medium Regressed: https://clusterfuzz.com/revisions?job=windows_asan_chrome_no_sandbox&range=533127:533139 Fixed: https://clusterfuzz.com/revisions?job=windows_asan_chrome_no_sandbox&range=557631:558316 Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5201753398837248 Additional requirements: Requires Gestures See https://github.com/google/clusterfuzz-tools for more information. If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
,
May 15 2018
ClusterFuzz testcase 5201753398837248 is verified as fixed, so closing issue as verified. If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
,
May 15 2018
,
May 29 2018
,
Jul 23
,
Aug 21
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
|||||||||||||||||||||||
►
Sign in to add a comment |
|||||||||||||||||||||||
Comment 1 by ClusterFuzz
, May 8 2018Owner: tsepez@chromium.org
Status: Assigned (was: Untriaged)