New issue
Advanced search Search tips

Issue 850474 link

Starred by 1 user

Issue metadata

Status: Duplicate
Merged: issue 664730
Owner:
Closed: Jun 2018
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Linux
Pri: 2
Type: Bug



Sign in to add a comment

Integer-overflow in FX_atonum

Project Member Reported by ClusterFuzz, Jun 7 2018

Issue description

Detailed report: https://clusterfuzz.com/testcase?key=5350851892477952

Fuzzer: attekett_surku_fuzzer
Job Type: linux_ubsan_chrome
Platform Id: linux

Crash Type: Integer-overflow
Crash Address: 
Crash State:
  FX_atonum
  CPDF_StreamContentParser::AddNumberParam
  CPDF_StreamContentParser::Parse
  
Sanitizer: undefined (UBSAN)

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5350851892477952

Issue filed automatically.

See https://github.com/google/clusterfuzz-tools for more information.
 
Cc: pnangunoori@chromium.org
Labels: M-69 Test-Predator-Wrong
Owner: thestig@chromium.org
Status: Assigned (was: Untriaged)
Predator and CL could not provide any possible suspects.
Using the code search for the file, “cpdf_streamcontentparser.cpp” assigning to concern owner from GIT revision log.

@thestig-- Could you please look into this issue as there are recent changes by you to the above file. Kindly reassign if it has nothing to do with your changes.

Thank You.

Components: Internals>Plugins>PDF
Labels: -M-69
Mergedinto: 664730
Status: Duplicate (was: Assigned)
Project Member

Comment 4 by ClusterFuzz, Jun 11 2018

ClusterFuzz has detected this issue as fixed in range 565833:565834.

Detailed report: https://clusterfuzz.com/testcase?key=5350851892477952

Fuzzer: attekett_surku_fuzzer
Job Type: linux_ubsan_chrome
Platform Id: linux

Crash Type: Integer-overflow
Crash Address: 
Crash State:
  FX_atonum
  CPDF_StreamContentParser::AddNumberParam
  CPDF_StreamContentParser::Parse
  
Sanitizer: undefined (UBSAN)

Fixed: https://clusterfuzz.com/revisions?job=linux_ubsan_chrome&range=565833:565834

Reproducer Testcase: https://clusterfuzz.com/download?testcase_id=5350851892477952

See https://github.com/google/clusterfuzz-tools for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.

Sign in to add a comment