GNOME Bugzilla – Bug 705421
Segfault in go_format_token2 on saving a fuzzed ods file
Last modified: 2013-08-03 20:50:11 UTC
Segfault in go_format_token2 on saving a fuzzed ods file. Git versions of glib, goffice, gnumeric, libgsf and libxml2. Test case: http://jutaky.com/fuzzing/gnumeric_case_4266_120.2ods.ods Backtrace from "ssconvert gnumeric_case_4266_120.2ods.ods out.ods" 0x00007ffff755555f in go_format_token2 (pstr=0x7fffffffddf0, ptt=0x7fffffffddec, localized=0) at utils/go-format.c:922 922 t = *(guchar *)str; (gdb) bt
+ Trace 232336
-- Juha Kylmänen Research Assistant, OUSPG
This problem has been fixed in the development version. The fix will be available in the next major software release. Thank you for your bug report.