GNOME Bugzilla – Bug 702409
Segfault on a corrupted (fuzzed) ods file in oo_parse_border
Last modified: 2013-06-16 18:50:35 UTC
Segfault on a corrupted (fuzzed) ods file in oo_parse_border. Git versions of glib, goffice, gnumeric, libgsf and libxml2. Test case: http://jutaky.com/fuzzing/gnumeric_case_16144_2869.ods Program received signal SIGSEGV, Segmentation fault. 0x00007fffe4747dd8 in oo_parse_border (xin=0x7fffffffdd80, style=0x8a4a18, str=0x8ba8e0 "0.035cm solid #000rap", location=MSTYLE_BORDER_TOP) at openoffice-read.c:6060 6060 border->width = pts; (gdb) bt
+ Trace 232075
-- Juha Kylmänen Research Assistant, OUSPG
This problem has been fixed in the development version. The fix will be available in the next major software release. Thank you for your bug report.