GNOME Bugzilla – Bug 624835
NULL-ptr derecence (write) in rsvg-filter.c:1211
Last modified: 2011-11-09 17:19:22 UTC
Library 2.31.0 compiled with '-O0 -g' Link: http://alt.swiecki.net/j/s/sigsegv5.svg $ gdb ./rsvg-convert (gdb) r "SIGSEGV.PC.0x420254.CODE.1.ADDR.(nil).INSTR.movsd_xmm0,_[rax].svg" Program received signal SIGSEGV, Segmentation fault. 0x0000000000420254 in rsvg_filter_primitive_convolve_matrix_set_atts (self=0x65ffd0, ctx=0x655000, atts=0x65dde0) at rsvg-filter.c:1211 1211 filter->divisor += filter->KernelMatrix[j + i * filter->orderx]; (gdb) p filter->KernelMatrix $1 = (double *) 0x0 0 0x0000000000420254 in rsvg_filter_primitive_convolve_matrix_set_atts (self=0x65ffd0, ct 1 0x0000000000413156 in rsvg_node_set_atts (node=0x65ffd0, ctx=0x655000, atts=0x65dde0) a 2 0x000000000040f99a in rsvg_standard_element_start (ctx=0x655000, name=0x6588d6 "feConvo 3 0x0000000000410714 in rsvg_start_element (data=0x655000, name=0x6588d6 "feConvolveMatri 4 0x00007ffff7604de3 in xmlParseStartTag () from /usr/lib/libxml2.so.2 5 0x00007ffff760ad82 in ?? () from /usr/lib/libxml2.so.2 6 0x00007ffff760bc01 in xmlParseChunk () from /usr/lib/libxml2.so.2 7 0x000000000041176b in rsvg_handle_write_impl (handle=0x655000, buf=0x64ffd0 "<?xml version=\"1.0\" encoding=\"UTF-8\"?>\r\n<!DOCTYPE svg PUBLIC \"-//W count=8744, error=0x7fffffffe4a8) at rsvg-base.c:1164 8 0x00000000004127ad in rsvg_handle_write (handle=0x655000, buf=0x64ffd0 "<?xml version=\"1.0\" encoding=\"UTF-8\"?>\r\n<!DOCTYPE svg PUBLIC \"-//W count=8744, error=0x7fffffffe4a8) at rsvg-base.c:1737 9 0x0000000000409dc5 in rsvg_handle_fill_with_data (handle=0x655000, data=0x64ffd0 "<?xml version=\"1.0\" encoding=\"UTF-8\"?>\r\n<!DOCTYPE svg PUBLIC \"-// , data_len=8744, error=0x7fffffffe4a8) at rsvg-base-file-util.c:38 10 0x0000000000409f36 in rsvg_handle_new_from_file (file_name=0x6465f0 "SIGSEGV.PC.0x42025 11 0x0000000000407775 in main (argc=1, argv=0x7fffffffe618) at rsvg-convert.c:228
Created attachment 170630 [details] [review] Patch
The URL is 404, can you attach the input file here please?
*** Bug 655606 has been marked as a duplicate of this bug. ***
There's a testcase in bug 655606 with attachment 192889 [details].
Fixed on master.