GNOME Bugzilla – Bug 702658
Segfault on a corrupted (fuzzed) gnumeric file in handle_delayed_names
Last modified: 2013-06-19 15:39:35 UTC
Segfault on a corrupted (fuzzed) gnumeric file in handle_delayed_names. Git versions of glib, goffice, gnumeric, libgsf and libxml2. Test case: http://jutaky.com/fuzzing/gnumeric_case_25553_194.gnumeric Program received signal SIGSEGV, Segmentation fault. 0x00007ffff79fc4d3 in handle_delayed_names (state=0x7fffffffe2e0) at xml-sax-read.c:2896 2896 nexpr->pos.eval = pp.eval; (gdb) bt
+ Trace 232104
-- Juha Kylmänen Research Assistant, OUSPG
This problem has been fixed in our software repository. The fix will go into the next software release. Thank you for your bug report.