easytag crashed with SIGSEGV in IA__gdk_color_copy()

Bug #907806 reported by iMac on 2011-12-22
18
This bug affects 2 people
Affects Status Importance Assigned to Milestone
easytag (Debian)
Fix Released
Unknown
easytag (Ubuntu)
Medium
Unassigned

Bug Description

Clicking around, in the process of saving one directory and scanning the next, and Crash.

ProblemType: Crash
DistroRelease: Ubuntu 11.10
Package: easytag 2.1.6+git20110423-3ubuntu1
ProcVersionSignature: Ubuntu 3.0.0-15.24-generic 3.0.13
Uname: Linux 3.0.0-15-generic x86_64
NonfreeKernelModules: fglrx
ApportVersion: 1.23-0ubuntu4
Architecture: amd64
Date: Thu Dec 22 10:15:00 2011
ExecutablePath: /usr/bin/easytag
ProcCmdline: easytag
ProcEnviron:
 PATH=(custom, no user)
 LANG=en_US.utf8
 SHELL=/bin/bash
SegvAnalysis:
 Segfault happened at: 0x7f4301cc41e3 <IA__gdk_color_copy+19>: mov (%rbx),%rdx
 PC (0x7f4301cc41e3) ok
 source "(%rbx)" (0x19000000190) not located in a known VMA region (needed readable region)!
 destination "%rdx" ok
SegvReason: reading unknown VMA
Signal: 11
SourcePackage: easytag
StacktraceTop:
 IA__gdk_color_copy (color=0x19000000190) at /build/buildd/gtk+2.0-2.24.6/gdk/gdkcolor.c:127
 boxed_proxy_collect_value (collect_values=<optimized out>, value=0x7ffface0ec30, n_collect_values=<optimized out>, collect_flags=<optimized out>) at /build/buildd/glib2.0-2.30.0/./gobject/gboxed.c:228
 boxed_proxy_collect_value (value=0x7ffface0ec30, n_collect_values=<optimized out>, collect_values=<optimized out>, collect_flags=<optimized out>) at /build/buildd/glib2.0-2.30.0/./gobject/gboxed.c:213
 gtk_list_store_set_valist_internal (list_store=0x26db710, iter=0x7ffface0f1e0, emit_signal=0x7ffface0ec98, maybe_need_sort=0x7ffface0ec9c, var_args=0x7ffface0ecc8) at /build/buildd/gtk+2.0-2.24.6/gtk/gtkliststore.c:802
 IA__gtk_list_store_set_valist (list_store=0x26db710, iter=0x7ffface0f1e0, var_args=0x7ffface0ecc8) at /build/buildd/gtk+2.0-2.24.6/gtk/gtkliststore.c:899
Title: easytag crashed with SIGSEGV in IA__gdk_color_copy()
UpgradeStatus: Upgraded to oneiric on 2011-10-28 (54 days ago)
UserGroups: adm admin cdrom dialout dip disk fax fuse libvirtd lpadmin mythtv netdev plugdev pulse pulse-access sambashare scanner tape vboxusers vde2-net video

Related branches

iMac (imac-netstatz) wrote :
iMac (imac-netstatz) wrote :

100% reproducible by just using the search function, with one or both of "File" and "Tag" selected.

StacktraceTop:
 IA__gdk_color_copy (color=0x19000000190) at /build/buildd/gtk+2.0-2.24.6/gdk/gdkcolor.c:127
 boxed_proxy_collect_value (collect_values=<optimized out>, value=0x7ffface0ec30, n_collect_values=<optimized out>, collect_flags=<optimized out>) at /build/buildd/glib2.0-2.30.0/./gobject/gboxed.c:228
 boxed_proxy_collect_value (value=0x7ffface0ec30, n_collect_values=<optimized out>, collect_values=<optimized out>, collect_flags=<optimized out>) at /build/buildd/glib2.0-2.30.0/./gobject/gboxed.c:213
 gtk_list_store_set_valist_internal (list_store=0x26db710, iter=0x7ffface0f1e0, emit_signal=0x7ffface0ec98, maybe_need_sort=0x7ffface0ec9c, var_args=0x7ffface0ecc8) at /build/buildd/gtk+2.0-2.24.6/gtk/gtkliststore.c:802
 IA__gtk_list_store_set_valist (list_store=0x26db710, iter=0x7ffface0f1e0, var_args=0x7ffface0ecc8) at /build/buildd/gtk+2.0-2.24.6/gtk/gtkliststore.c:899

Changed in easytag (Ubuntu):
importance: Undecided → Medium
tags: removed: need-amd64-retrace
Launchpad Janitor (janitor) wrote :

Status changed to 'Confirmed' because the bug affects multiple users.

Changed in easytag (Ubuntu):
status: New → Confirmed
Julian Taylor (jtaylor) wrote :

caused by this:
misc.c:2573:23: warning: array subscript is above array bounds [-Warray-bounds]

easy to fix, I'll upload a new version to precise.

Changed in easytag (Ubuntu):
status: Confirmed → Triaged
Julian Taylor (jtaylor) on 2012-04-18
visibility: private → public
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package easytag - 2.1.7-1ubuntu2

---------------
easytag (2.1.7-1ubuntu2) precise; urgency=low

  * add fix-out-of-bound.patch to fix buffer overflow on search (LP: #907806)
 -- Julian Taylor <email address hidden> Wed, 18 Apr 2012 21:41:55 +0200

Changed in easytag (Ubuntu):
status: Triaged → Fix Released
Changed in easytag (Debian):
status: Unknown → Confirmed
Changed in easytag (Debian):
status: Confirmed → Fix Released
To post a comment you must log in.
This report contains Public information  Edit
Everyone can see this information.

Duplicates of this bug

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.