GNOME Bugzilla – Bug 703006
Segfault in xml_sax_solver_start on a corrupted (fuzzed) gnumeric file
Last modified: 2013-06-24 19:33:46 UTC
Segfault in xml_sax_solver_start on a corrupted (fuzzed) gnumeric file. Git versions of glib, goffice, gnumeric, libgsf and libxml2. Test case: http://jutaky.com/fuzzing/gnumeric_case_17903_1415.gnumeric Program received signal SIGSEGV, Segmentation fault. 0x00007ffff79fb4a7 in xml_sax_solver_start (xin=0x7fffffffe170, attrs=0x8f2090) at xml-sax-read.c:2511 2511 GnmSolverParameters *sp = sheet->solver_parameters; (gdb) bt
+ Trace 232139
-- Juha Kylmänen Research Assistant, OUSPG
This problem has been fixed in our software repository. The fix will go into the next software release. Thank you for your bug report.