Segfault on small sample input
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
Inkscape |
Fix Released
|
Undecided
|
Unassigned |
Bug Description
When opening this file with inkscape I get a segfault. Discovered with AFL: http://
inkscape is run with: inkscape --without-gui -e - id:000000,
I'm not sure if this is security relevant. Relevant output in GDB:
/media/
^
/media/
^
Program received signal SIGSEGV, Segmentation fault.
0x00007fffef9496b4 in free () from /lib64/libc.so.6
(gdb) bt
#0 0x00007fffef9496b4 in free () from /lib64/libc.so.6
#1 0x0000000001899a4d in ~GzipInputStream (this=0x27da060, __in_chrg=
#2 Inkscape:
at io/gzipstream.
#3 0x0000000000fa2d46 in close (this=0x7ffffff
#4 XmlSource::closeCb (context=
#5 0x00007ffff44b363b in xmlFreeParserIn
#6 0x00007ffff44873d6 in xmlFreeInputStream () from /usr/lib64/
#7 0x00007ffff4487f40 in xmlFreeParserCtxt () from /usr/lib64/
#8 0x00007ffff449dbb1 in xmlDoRead () from /usr/lib64/
#9 0x0000000000fa4613 in XmlSource::readXml (this=this@
#10 0x0000000000fa6b2b in sp_repr_read_file (
filename=
default_
#11 0x00000000004ad9b2 in sp_document_new (
uri=0x27d9450 "/media/
make_
#12 0x0000000000a4500d in Inkscape:
filename=
at extension/
#13 0x000000000049207e in sp_process_
#14 0x0000000000495552 in sp_main_console (argc=5, argv=0x7fffffff
#15 0x000000000046090f in main (argc=5, argv=0x7fffffff
#16 0x00007fffef8eddc5 in __libc_start_main () from /lib64/libc.so.6
#17 0x000000000048aad9 in _start ()
tags: | added: cli crash |
information type: | Private Security → Public |
Closing because it now doesn't crash in master (or in 0.92 actually).
Closed by: https:/ /gitlab. com/doctormo