GNOME Bugzilla – Bug 703149
Segfault on a corrupted (fuzzed) html file
Last modified: 2013-06-27 20:12:54 UTC
Segfault on a corrupted (fuzzed) html file. Git versions of glib, goffice, gnumeric, libgsf and libxml2. Test case: http://jutaky.com/fuzzing/gnumeric_case_19438_343.html Program received signal SIGSEGV, Segmentation fault. 0x00007fffe6beda87 in html_read_content (cur=0x946590, buf=0xab4c00, mstyle=0xa4cad0, a_buf=0xab58d0, hrefs=0x7fffffffdca8, first=1, doc=0x611cf0, tc=0x7fffffffe3d0) at html_read.c:155 155 g_string_append_printf (buf, _("[see sheet %s]"), tc->sheet->name_quoted); (gdb) bt
+ Trace 232152
-- Juha Kylmänen Research Assistant, OUSPG
This problem has been fixed in the development version. The fix will be available in the next major software release. Thank you for your bug report.