soffice.bin crashed with SIGSEGV in SvxNumOptionsTabPage::InitControls()

Bug #1031537 reported by Scott Kitterman on 2012-07-31
libreoffice (Ubuntu)

Bug Description

I was editing a slide in impress when the crash happened.

ProblemType: Crash
DistroRelease: Ubuntu 12.04
Package: libreoffice-core 1:3.5.4-0ubuntu1
ProcVersionSignature: Ubuntu 3.2.0-27.43-generic-pae 3.2.21
Uname: Linux 3.2.0-27-generic-pae i686
ApportVersion: 2.0.1-0ubuntu11
Architecture: i386
Date: Tue Jul 31 18:43:26 2012
EcryptfsInUse: Yes
ExecutablePath: /usr/lib/libreoffice/program/soffice.bin
InstallationMedia: Kubuntu 11.04 "Natty Narwhal" - Beta i386 (20110330)
ProcCmdline: /usr/lib/libreoffice/program/soffice.bin --impress --splash-pipe=6
 Segfault happened at: 0xa84e4840: mov 0x5c(%esp,%esi,4),%eax
 PC (0xa84e4840) ok
 source "0x5c(%esp,%esi,4)" (0xbfddd1a8) not located in a known VMA region (needed readable region)!
 destination "%eax" ok
SegvReason: reading unknown VMA
Signal: 11
SourcePackage: libreoffice
 ?? () from /usr/lib/libreoffice/program/
 ?? () from /usr/lib/libreoffice/program/
 ?? () from /usr/lib/libreoffice/program/
 ?? () from /usr/lib/libreoffice/program/
 SfxTabDialog::Execute() () from /usr/lib/libreoffice/program/
Title: soffice.bin crashed with SIGSEGV in SfxTabDialog::Execute()
UpgradeStatus: Upgraded to precise on 2012-04-09 (113 days ago)
UserGroups: adm admin audio cdrom dialout lpadmin plugdev sambashare syslog wireshark

Scott Kitterman (kitterman) wrote :

 SvxNumOptionsTabPage::InitControls (this=0xad2ae58) at /build/buildd/libreoffice-3.5.4/cui/source/tabpages/numpages.cxx:3597
 SvxNumOptionsTabPage::Reset (this=0xad2ae58, rSet=...) at /build/buildd/libreoffice-3.5.4/cui/source/tabpages/numpages.cxx:1438
 SfxTabDialog::ActivatePageHdl (this=0xad01398, pTabCtrl=0xad014e8) at /build/buildd/libreoffice-3.5.4/sfx2/source/dialog/tabdlg.cxx:1259
 SfxTabDialog::Start_Impl (this=0xad01398) at /build/buildd/libreoffice-3.5.4/sfx2/source/dialog/tabdlg.cxx:701
 Execute (this=0xad01398) at /build/buildd/libreoffice-3.5.4/sfx2/source/dialog/tabdlg.cxx:586

Scott Kitterman, thank you for reporting this bug and helping make Ubuntu better. Could you please attach an example file, with specific, click-for-click instructions, on how to reproduce this crash?

Scott Kitterman (kitterman) wrote :

No. It's not reproducible even with the same file. It seemed to freeze up after I had tried selecting all four format boxes on the four box slide template and changed the default bullet arrangement. When I clicked into on of the boxes it froze or it may have been just after when I clicked on the bullet config icon in the toolbar.

Scott Kitterman (kitterman) wrote :

It just happened again and it's definitely related to working inside a text box in impress. This time I was rapidly hitting ctrl-z to undo something and LO froze for several seconds and then crashed.

Happened again. This time I was definitely clicking on the bullets icon in the

