GNOME Bugzilla – Bug 702485
Segfault on a corrupted (fuzzed) xlsx file in dependent_set_expr
Last modified: 2013-06-17 16:58:38 UTC
Segfault on a corrupted (fuzzed) xlsx file in dependent_set_expr. Git versions of glib, goffice, gnumeric, libgsf and libxml2. Test case: http://jutaky.com/fuzzing/gnumeric_case_3089_7177.xlsx Program received signal SIGSEGV, Segmentation fault. 0x00007ffff78d12ad in dependent_set_expr (dep=0x18, new_texpr=0x3cfebb0) at dependent.c:408 408 int const t = dependent_type (dep); (gdb) bt
+ Trace 232080
-- Juha Kylmänen Research Assistant, OUSPG
This problem has been fixed in the development version. The fix will be available in the next major software release. Thank you for your bug report.