GNOME Bugzilla – Bug 702285
Segfault on a corrupted (fuzzed) ods file in odf_custom_shape_end
Last modified: 2013-06-14 20:07:46 UTC
Segfault on a corrupted (fuzzed) ods file in odf_custom_shape_end. Git versions of glib, goffice, gnumeric, libgsf and libxml2. Test case: http://jutaky.com/fuzzing/gnumeric_case_16926_1425.ods Program received signal SIGSEGV, Segmentation fault. 0x00007fffe4753192 in odf_custom_shape_end (xin=0x7fffffffdd90, blob=0x0) at openoffice-read.c:9547 9547 for (cur = strs; *cur != NULL; cur++) { (gdb) bt
+ Trace 232065
-- Juha Kylmänen Research Assistant, OUSPG
This problem has been fixed in the development version. The fix will be available in the next major software release. Thank you for your bug report.