Closed Bug 580730 Opened 13 years ago Closed 13 years ago
Invalid values in TT's glyf table leading to crash [@TSparse
Coords List Per Composits::Get Coords()]
Build identifier: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.6; en-US; rv:2.0b2pre) Gecko/20100718 Minefield/4.0b2pre I am testing something new. Currently I can't provide you guys with the exact values/tables. Load the provided html file.
Christoph, any idea what table/offsets you were fuzzing? It would really help tracking down the cause. I'm guessing somewhere in the glyf table but that probably needs to be verified. For OSX cases, could you note when a testcase also crashes in Safari? That helps raise the priority when reporting it to Apple.
John, it is the glyf table. I am currently trying to reduce the testcase. Yes, Safari is affected too.
Summary: Invalid values in TT font leading to crash [@TSparseCoordsListPerComposits::GetCoords()] → Invalid values in TT's glyf table leading to crash [@TSparseCoordsListPerComposits::GetCoords()]
Crashes in Safari on 10.6.4 but not 10.5.8.
Logged rdar://8233435 with Apple.
testcase.zip includes: values.txt
Attachment #459103 - Attachment is obsolete: true
This is fixed on trunk and 1.9.2 by the sanitizer blocking the fuzzed font.
Verified fixed in 184.108.40.206 with Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10.6; en-US; rv:220.127.116.11pre) Gecko/20101118 Namoroka/3.6.13pre using testcase. Test no longer crashes as it does in 18.104.22.168. (This was tested on OS X 10.6.5 but crash was verified first.)
You need to log in before you can comment on or make changes to this bug.