https://bugs.freedesktop.org/show_bug.cgi?id=70480

          Priority: medium
            Bug ID: 70480
          Assignee: libreoffice-bugs@lists.freedesktop.org
           Summary: FILEOPEN: SIGSEGV when supplying malformed input files
                    to Writer
          Severity: normal
    Classification: Unclassified
                OS: Linux (All)
          Reporter: ioan-alexandru.bla...@intel.com
          Hardware: Other
        Whiteboard: BSA
            Status: UNCONFIRMED
           Version: 4.1.2.3 rc
         Component: Writer
           Product: LibreOffice

Created attachment 87651
  --> https://bugs.freedesktop.org/attachment.cgi?id=87651&action=edit
files that can be used to reproduce the crash

Problem description: 

Program received signal SIGSEGV, Segmentation fault.
std::basic_string<char, std::char_traits<char>, std::allocator<char>
>::basic_string (this=0x7fffffffb478, __str=
    <error reading variable: Cannot access memory at address 0x29>)
    at
/usr/src/debug/gcc-4.7.2/obj-x86_64-tizen-linux/x86_64-tizen-linux/libstdc++-v3/include/bits/basic_string.tcc:175

A number of files that can be used to reproduce the crash can be found in the
attached crash_files.zip archive. 
The files were generated by fuzzing valid files, in order to check for problems
when libreoffice handles malformed input.
The bug was found while testing Libreoffice version 4.0.1.2, but it is
persistent in version 4.1.2.3

Steps to reproduce:
1. Open libreoffice with gdb attached
2. Open the files from crash_files.zip

A gdb backtrace example of opening one of the files can be found here:
https://docs.google.com/file/d/0Bw_O6opVYHaaYVIwRlNOMkJfOUk/edit?usp=sharing


Operating System: Ubuntu
Version: 4.1.2.3 rc

-- 
You are receiving this mail because:
You are the assignee for the bug.
_______________________________________________
Libreoffice-bugs mailing list
Libreoffice-bugs@lists.freedesktop.org
http://lists.freedesktop.org/mailman/listinfo/libreoffice-bugs

Reply via email to