We want to share that the latest version (2022.0.0) of pto_merge causes another heap-buffer-overflow bug in the function HuginBase::PTools::setDestImage as well as in the function HuginBase::PanoramaMemento::loadPTScript.
The invalid memory allocation may attribute to the malformed values as parameters to the HuginBase::PTools::setDestImage .
Here is the output of program with address sanitizer attached.
Bug Report
ERROR: 13:28:41.047604 (/home/ubuntu/targets/hugin-2022.0.0_original/src/hugin_base/panotools/PanoToolsInterface.cpp:357) setDestImage(): unsupported projection
=================================================================
==4011==ERROR: AddressSanitizer: heap-buffer-overflow on address 0x603000009808 at pc 0x7f973bddfdeb bp 0x7fff0426e670 sp 0x7fff0426e660
READ of size 8 at 0x603000009808 thread T0
#0 0x7f973bddfdea in HuginBase::PTools::setDestImage(Image&, vigra::Diff2D, unsigned char*, HuginBase::PanoramaOptions::ProjectionFormat const&, std::vector<double, std::allocator<double> > const&, double) /home/ubuntu/targets/hugin-2022.0.0_original/src/hugin_base/panotools/PanoToolsInterface.cpp:362
#1 0x7f973bde173e in HuginBase::PTools::Transform::updatePTData(vigra::Diff2D const&, std::map<std::__cxx11::basic_string<char, std::char_traits<char>, std::allocator<char> >, HuginBase::Variable, std::less<std::__cxx11::basic_string<char, std::char_traits<char>, std::allocator<char> > >, std::allocator<std::pair<std::__cxx11::basic_string<char, std::char_traits<char>, std::allocator<char> > const, HuginBase::Variable> > > const&, HuginBase::BaseSrcPanoImage::Projection&, vigra::Diff2D const&, HuginBase::PanoramaOptions::ProjectionFormat&, std::vector<double, std::allocator<double> > const&, double) /home/ubuntu/targets/hugin-2022.0.0_original/src/hugin_base/panotools/PanoToolsInterface.cpp:66
#2 0x7f973bde1b53 in HuginBase::PTools::Transform::createTransform(vigra::Diff2D const&, std::map<std::__cxx11::basic_string<char, std::char_traits<char>, std::allocator<char> >, HuginBase::Variable, std::less<std::__cxx11::basic_string<char, std::char_traits<char>, std::allocator<char> > >, std::allocator<std::pair<std::__cxx11::basic_string<char, std::char_traits<char>, std::allocator<char> > const, HuginBase::Variable> > >, HuginBase::BaseSrcPanoImage::Projection, vigra::Diff2D const&, HuginBase::PanoramaOptions::ProjectionFormat, std::vector<double, std::allocator<double> > const&, double, vigra::Diff2D const&) /home/ubuntu/targets/hugin-2022.0.0_original/src/hugin_base/panotools/PanoToolsInterface.cpp:181
#3 0x7f973bded5d8 in HuginBase::PTools::Transform::createTransform(HuginBase::SrcPanoImage const&, HuginBase::PanoramaOptions const&) /home/ubuntu/targets/hugin-2022.0.0_original/src/hugin_base/panotools/PanoToolsInterface.cpp:147
#4 0x7f973bcef22b in HuginBase::PanoramaOptions::getVFOV() const /home/ubuntu/targets/hugin-2022.0.0_original/src/hugin_base/panodata/PanoramaOptions.cpp:358
#5 0x7f973bcf131d in HuginBase::PanoramaOptions::setProjectionParameters(std::vector<double, std::allocator<double> > const&) /home/ubuntu/targets/hugin-2022.0.0_original/src/hugin_base/panodata/PanoramaOptions.cpp:190
#6 0x7f973bcf1858 in HuginBase::PanoramaOptions::resetProjectionParameters() /home/ubuntu/targets/hugin-2022.0.0_original/src/hugin_base/panodata/PanoramaOptions.cpp:200
#7 0x7f973bc722b9 in HuginBase::PanoramaMemento::loadPTScript(std::istream&, int&, std::__cxx11::basic_string<char, std::char_traits<char>, std::allocator<char> > const&) /home/ubuntu/targets/hugin-2022.0.0_original/src/hugin_base/panodata/Panorama.cpp:2492
#8 0x7f973bc9c618 in HuginBase::Panorama::readData(std::istream&, std::__cxx11::basic_string<char, std::char_traits<char>, std::allocator<char> >) /home/ubuntu/targets/hugin-2022.0.0_original/src/hugin_base/panodata/Panorama.cpp:2178
#9 0x555e5c6e1975 in main /home/ubuntu/targets/hugin-2022.0.0_original/src/tools/pto_merge.cpp:99
#10 0x7f9739390082 in __libc_start_main ../csu/libc-start.c:308
#11 0x555e5c6e2c5d in _start (/home/ubuntu/targets/hugin-2022.0.0_original/build/src/tools/pto_merge+0xbc5d)
0x603000009808 is located 0 bytes to the right of 24-byte region [0x6030000097f0,0x603000009808)
allocated by thread T0 here:
#0 0x7f973c13a587 in operator new(unsigned long) ../../../../src/libsanitizer/asan/asan_new_delete.cc:104
#1 0x7f973ac7c9a5 in __gnu_cxx::new_allocator<double>::allocate(unsigned long, void const*) /usr/include/c++/9/ext/new_allocator.h:114
#2 0x7f973ac7c9a5 in std::allocator_traits<std::allocator<double> >::allocate(std::allocator<double>&, unsigned long) /usr/include/c++/9/bits/alloc_traits.h:443
#3 0x7f973ac7c9a5 in std::_Vector_base<double, std::allocator<double> >::_M_allocate(unsigned long) /usr/include/c++/9/bits/stl_vector.h:343
#4 0x7f973ac7c9a5 in std::vector<double, std::allocator<double> >::_M_default_append(unsigned long) /usr/include/c++/9/bits/vector.tcc:635
#5 0x7f973bcf1ab7 in std::vector<double, std::allocator<double> >::resize(unsigned long) /usr/include/c++/9/bits/stl_vector.h:937
#6 0x7f973bcf1ab7 in HuginBase::PanoramaOptions::setProjection(HuginBase::PanoramaOptions::ProjectionFormat) /home/ubuntu/targets/hugin-2022.0.0_original/src/hugin_base/panodata/PanoramaOptions.cpp:154
#7 0x7f973bc722b9 in HuginBase::PanoramaMemento::loadPTScript(std::istream&, int&, std::__cxx11::basic_string<char, std::char_traits<char>, std::allocator<char> > const&) /home/ubuntu/targets/hugin-2022.0.0_original/src/hugin_base/panodata/Panorama.cpp:2492
#8 0x7f973bc9c618 in HuginBase::Panorama::readData(std::istream&, std::__cxx11::basic_string<char, std::char_traits<char>, std::allocator<char> >) /home/ubuntu/targets/hugin-2022.0.0_original/src/hugin_base/panodata/Panorama.cpp:2178
#9 0x555e5c6e1975 in main /home/ubuntu/targets/hugin-2022.0.0_original/src/tools/pto_merge.cpp:99
#10 0x7f9739390082 in __libc_start_main ../csu/libc-start.c:308
SUMMARY: AddressSanitizer: heap-buffer-overflow /home/ubuntu/targets/hugin-2022.0.0_original/src/hugin_base/panotools/PanoToolsInterface.cpp:362 in HuginBase::PTools::setDestImage(Image&, vigra::Diff2D, unsigned char*, HuginBase::PanoramaOptions::ProjectionFormat const&, std::vector<double, std::allocator<double> > const&, double)
Shadow bytes around the buggy address:
0x0c067fff92b0: fd fd fd fa fa fa fd fd fd fa fa fa fd fd fd fa
0x0c067fff92c0: fa fa fd fd fd fa fa fa fd fd fd fa fa fa fd fd
0x0c067fff92d0: fd fa fa fa fd fd fd fa fa fa fd fd fd fa fa fa
0x0c067fff92e0: fd fd fd fa fa fa fd fd fd fa fa fa fd fd fd fd
0x0c067fff92f0: fa fa fd fd fd fd fa fa fd fd fd fd fa fa 00 00
=>0x0c067fff9300: 00[fa]fa fa fd fd fd fa fa fa fd fd fd fd fa fa
0x0c067fff9310: fd fd fd fa fa fa fd fd fd fa fa fa fd fd fd fa
0x0c067fff9320: fa fa fd fd fd fa fa fa fd fd fd fa fa fa fd fd
0x0c067fff9330: fd fa fa fa fd fd fd fa fa fa fd fd fd fa fa fa
0x0c067fff9340: fd fd fd fa fa fa fd fd fd fa fa fa fd fd fd fa
0x0c067fff9350: fa fa fd fd fd fa fa fa fd fd fd fa fa fa fd fd
Shadow byte legend (one shadow byte represents 8 application bytes):
Addressable: 00
Partially addressable: 01 02 03 04 05 06 07
Heap left redzone: fa
Freed heap region: fd
Stack left redzone: f1
Stack mid redzone: f2
Stack right redzone: f3
Stack after return: f5
Stack use after scope: f8
Global redzone: f9
Global init order: f6
Poisoned by user: f7
Container overflow: fc
Array cookie: ac
Intra object redzone: bb
ASan internal: fe
Left alloca redzone: ca
Right alloca redzone: cb
Shadow gap: cc
==4011==ABORTING
### Envionment
OS: Ubuntu 20.04.5 LTS x86_64
Release: hugin 2022.0.0
Program: pto_merge
To reproduce the problem, we need to build hugin:
sudo cmake -DCMAKE_C_FLAGS="-g" -DCMAKE_CXX_FLAGS="-g" ..
### How to reproduce
$ pto_merge poc-file *.jpg
(*.jpg any name of jpg file including asterisk(*))
poc-file is attached.
Hi there
We want to share that the latest version (2022.0.0) of pto_merge causes another heap-buffer- overflow bug in the function HuginBase: :PTools: :setDestImage as well as in the function HuginBase: :PanoramaMement o::loadPTScript .
The invalid memory allocation may attribute to the malformed values as parameters to the HuginBase: :PTools: :setDestImage .
Here is the output of program with address sanitizer attached.
Bug Report
ERROR: 13:28:41.047604 (/home/ ubuntu/ targets/ hugin-2022. 0.0_original/ src/hugin_ base/panotools/ PanoToolsInterf ace.cpp: 357) setDestImage(): unsupported projection ======= ======= ======= ======= ======= ======= ======= ======= == overflow on address 0x603000009808 at pc 0x7f973bddfdeb bp 0x7fff0426e670 sp 0x7fff0426e660 :PTools: :setDestImage( Image&, vigra::Diff2D, unsigned char*, HuginBase: :PanoramaOption s::ProjectionFo rmat const&, std::vector<double, std::allocator< double> > const&, double) /home/ubuntu/ targets/ hugin-2022. 0.0_original/ src/hugin_ base/panotools/ PanoToolsInterf ace.cpp: 362 :PTools: :Transform: :updatePTData( vigra:: Diff2D const&, std::map< std::__ cxx11:: basic_string< char, std::char_ traits< char>, std::allocator< char> >, HuginBase: :Variable, std::less< std::__ cxx11:: basic_string< char, std::char_ traits< char>, std::allocator< char> > >, std::allocator< std::pair< std::__ cxx11:: basic_string< char, std::char_ traits< char>, std::allocator< char> > const, HuginBase: :Variable> > > const&, HuginBase: :BaseSrcPanoIma ge::Projection& , vigra::Diff2D const&, HuginBase: :PanoramaOption s::ProjectionFo rmat&, std::vector<double, std::allocator< double> > const&, double) /home/ubuntu/ targets/ hugin-2022. 0.0_original/ src/hugin_ base/panotools/ PanoToolsInterf ace.cpp: 66 :PTools: :Transform: :createTransfor m(vigra: :Diff2D const&, std::map< std::__ cxx11:: basic_string< char, std::char_ traits< char>, std::allocator< char> >, HuginBase: :Variable, std::less< std::__ cxx11:: basic_string< char, std::char_ traits< char>, std::allocator< char> > >, std::allocator< std::pair< std::__ cxx11:: basic_string< char, std::char_ traits< char>, std::allocator< char> > const, HuginBase: :Variable> > >, HuginBase: :BaseSrcPanoIma ge::Projection, vigra::Diff2D const&, HuginBase: :PanoramaOption s::ProjectionFo rmat, std::vector<double, std::allocator< double> > const&, double, vigra::Diff2D const&) /home/ubuntu/ targets/ hugin-2022. 0.0_original/ src/hugin_ base/panotools/ PanoToolsInterf ace.cpp: 181 :PTools: :Transform: :createTransfor m(HuginBase: :SrcPanoImage const&, HuginBase: :PanoramaOption s const&) /home/ubuntu/ targets/ hugin-2022. 0.0_original/ src/hugin_ base/panotools/ PanoToolsInterf ace.cpp: 147 :PanoramaOption s::getVFOV( ) const /home/ubuntu/ targets/ hugin-2022. 0.0_original/ src/hugin_ base/panodata/ PanoramaOptions .cpp:358 :PanoramaOption s::setProjectio nParameters( std::vector< double, std::allocator< double> > const&) /home/ubuntu/ targets/ hugin-2022. 0.0_original/ src/hugin_ base/panodata/ PanoramaOptions .cpp:190 :PanoramaOption s::resetProject ionParameters( ) /home/ubuntu/ targets/ hugin-2022. 0.0_original/ src/hugin_ base/panodata/ PanoramaOptions .cpp:200 :PanoramaMement o::loadPTScript (std::istream& , int&, std::__ cxx11:: basic_string< char, std::char_ traits< char>, std::allocator< char> > const&) /home/ubuntu/ targets/ hugin-2022. 0.0_original/ src/hugin_ base/panodata/ Panorama. cpp:2492 :Panorama: :readData( std::istream& , std::__ cxx11:: basic_string< char, std::char_ traits< char>, std::allocator< char> >) /home/ubuntu/ targets/ hugin-2022. 0.0_original/ src/hugin_ base/panodata/ Panorama. cpp:2178 targets/ hugin-2022. 0.0_original/ src/tools/ pto_merge. cpp:99 libc-start. c:308 ubuntu/ targets/ hugin-2022. 0.0_original/ build/src/ tools/pto_ merge+0xbc5d)
=======
==4011==ERROR: AddressSanitizer: heap-buffer-
READ of size 8 at 0x603000009808 thread T0
#0 0x7f973bddfdea in HuginBase:
#1 0x7f973bde173e in HuginBase:
#2 0x7f973bde1b53 in HuginBase:
#3 0x7f973bded5d8 in HuginBase:
#4 0x7f973bcef22b in HuginBase:
#5 0x7f973bcf131d in HuginBase:
#6 0x7f973bcf1858 in HuginBase:
#7 0x7f973bc722b9 in HuginBase:
#8 0x7f973bc9c618 in HuginBase:
#9 0x555e5c6e1975 in main /home/ubuntu/
#10 0x7f9739390082 in __libc_start_main ../csu/
#11 0x555e5c6e2c5d in _start (/home/
0x603000009808 is located 0 bytes to the right of 24-byte region [0x6030000097f0 ,0x603000009808 ) ./../src/ libsanitizer/ asan/asan_ new_delete. cc:104 :new_allocator< double> ::allocate( unsigned long, void const*) /usr/include/ c++/9/ext/ new_allocator. h:114 traits< std::allocator< double> >::allocate( std::allocator< double> &, unsigned long) /usr/include/ c++/9/bits/ alloc_traits. h:443 base<double, std::allocator< double> >::_M_allocate( unsigned long) /usr/include/ c++/9/bits/ stl_vector. h:343 double> >::_M_default_ append( unsigned long) /usr/include/ c++/9/bits/ vector. tcc:635 double> >::resize(unsigned long) /usr/include/ c++/9/bits/ stl_vector. h:937 :PanoramaOption s::setProjectio n(HuginBase: :PanoramaOption s::ProjectionFo rmat) /home/ubuntu/ targets/ hugin-2022. 0.0_original/ src/hugin_ base/panodata/ PanoramaOptions .cpp:154 :PanoramaMement o::loadPTScript (std::istream& , int&, std::__ cxx11:: basic_string< char, std::char_ traits< char>, std::allocator< char> > const&) /home/ubuntu/ targets/ hugin-2022. 0.0_original/ src/hugin_ base/panodata/ Panorama. cpp:2492 :Panorama: :readData( std::istream& , std::__ cxx11:: basic_string< char, std::char_ traits< char>, std::allocator< char> >) /home/ubuntu/ targets/ hugin-2022. 0.0_original/ src/hugin_ base/panodata/ Panorama. cpp:2178 targets/ hugin-2022. 0.0_original/ src/tools/ pto_merge. cpp:99 libc-start. c:308
allocated by thread T0 here:
#0 0x7f973c13a587 in operator new(unsigned long) ../../.
#1 0x7f973ac7c9a5 in __gnu_cxx:
#2 0x7f973ac7c9a5 in std::allocator_
#3 0x7f973ac7c9a5 in std::_Vector_
#4 0x7f973ac7c9a5 in std::vector<double, std::allocator<
#5 0x7f973bcf1ab7 in std::vector<double, std::allocator<
#6 0x7f973bcf1ab7 in HuginBase:
#7 0x7f973bc722b9 in HuginBase:
#8 0x7f973bc9c618 in HuginBase:
#9 0x555e5c6e1975 in main /home/ubuntu/
#10 0x7f9739390082 in __libc_start_main ../csu/
SUMMARY: AddressSanitizer: heap-buffer- overflow /home/ubuntu/ targets/ hugin-2022. 0.0_original/ src/hugin_ base/panotools/ PanoToolsInterf ace.cpp: 362 in HuginBase: :PTools: :setDestImage( Image&, vigra::Diff2D, unsigned char*, HuginBase: :PanoramaOption s::ProjectionFo rmat const&, std::vector<double, std::allocator< double> > const&, double)
Shadow bytes around the buggy address:
0x0c067fff92b0: fd fd fd fa fa fa fd fd fd fa fa fa fd fd fd fa
0x0c067fff92c0: fa fa fd fd fd fa fa fa fd fd fd fa fa fa fd fd
0x0c067fff92d0: fd fa fa fa fd fd fd fa fa fa fd fd fd fa fa fa
0x0c067fff92e0: fd fd fd fa fa fa fd fd fd fa fa fa fd fd fd fd
0x0c067fff92f0: fa fa fd fd fd fd fa fa fd fd fd fd fa fa 00 00
=>0x0c067fff9300: 00[fa]fa fa fd fd fd fa fa fa fd fd fd fd fa fa
0x0c067fff9310: fd fd fd fa fa fa fd fd fd fa fa fa fd fd fd fa
0x0c067fff9320: fa fa fd fd fd fa fa fa fd fd fd fa fa fa fd fd
0x0c067fff9330: fd fa fa fa fd fd fd fa fa fa fd fd fd fa fa fa
0x0c067fff9340: fd fd fd fa fa fa fd fd fd fa fa fa fd fd fd fa
0x0c067fff9350: fa fa fd fd fd fa fa fa fd fd fd fa fa fa fd fd
Shadow byte legend (one shadow byte represents 8 application bytes):
Addressable: 00
Partially addressable: 01 02 03 04 05 06 07
Heap left redzone: fa
Freed heap region: fd
Stack left redzone: f1
Stack mid redzone: f2
Stack right redzone: f3
Stack after return: f5
Stack use after scope: f8
Global redzone: f9
Global init order: f6
Poisoned by user: f7
Container overflow: fc
Array cookie: ac
Intra object redzone: bb
ASan internal: fe
Left alloca redzone: ca
Right alloca redzone: cb
Shadow gap: cc
==4011==ABORTING
### Envionment C_FLAGS= "-g" -DCMAKE_ CXX_FLAGS= "-g" ..
OS: Ubuntu 20.04.5 LTS x86_64
Release: hugin 2022.0.0
Program: pto_merge
To reproduce the problem, we need to build hugin:
sudo cmake -DCMAKE_
### How to reproduce
$ pto_merge poc-file *.jpg
(*.jpg any name of jpg file including asterisk(*))
poc-file is attached.