GNOME Bugzilla – Bug 703670
Segfault in load_image on a corrupted (fuzzed) gnumeric file
Last modified: 2013-07-05 21:13:32 UTC
Segfault in load_image on a corrupted (fuzzed) gnumeric file. Git versions of glib, goffice, gnumeric, libgsf and libxml2. Test case: http://jutaky.com/fuzzing/gnumeric_case_11093_97511.gnumeric Program received signal SIGSEGV, Segmentation fault. 0x00007ffff7496d06 in load_image (xin=0x7fffffffe1a0, attrs=0x0) at app/go-doc.c:554 554 if (!*attr) (gdb) bt
+ Trace 232194
-- Juha Kylmänen Research Assistant, OUSPG
This problem has been fixed in the development version of goffice. The fix will be available in the next major software release. Thank you for your bug report.