GNOME Bugzilla – Bug 704102
Segfault in sc_parse_format_set_type on a corrupted (fuzzed) sc file
Last modified: 2013-07-15 18:32:59 UTC
Segfault in sc_parse_format_set_type on a corrupted (fuzzed) sc file. Git versions of glib, goffice, gnumeric, libgsf and libxml2. Test case: http://jutaky.com/fuzzing/gnumeric_case_1483_3.sc Program received signal SIGSEGV, Segmentation fault. 0x00007fffe6a9debf in sc_parse_format_set_type (state=0x7fffffffe3d0, type=-119581439, col_from=228, col_to=228) at sc.c:467 467 char const *o_format = g_ptr_array_index(state->formats, type); (gdb) bt
+ Trace 232231
-- Juha Kylmänen Research Assistant, OUSPG
This problem has been fixed in our software repository. The fix will go into the next software release. Thank you for your bug report.