Crashes with *** stack smashing detected *** message

Bug #61742 reported by Yagisan
This bug report is a duplicate of:  Bug #58508: cant save under edgy. Edit Remove
2
Affects Status Importance Assigned to Milestone
openoffice.org (Ubuntu)
Fix Released
Undecided
Matthias Klose

Bug Description

Binary package hint: openoffice.org-writer-experimental

Installed openoffice.org-writer-experimental as it is the only OO.o that will install on my amd64 system at this time.:

apt-cache show openoffice.org-writer-experimental
Package: openoffice.org-writer-experimental
Priority: optional
Section: universe/editors
Installed-Size: 15868
Maintainer: Debian OpenOffice Team <email address hidden>
Architecture: amd64
Source: openoffice.org
Version: 2.0.3-6ubuntu1
Replaces: openoffice.org (<< 1.9), openoffice.org-debian-files, openoffice.org2-writer-experimental
Provides: openoffice.org2-writer, openoffice.org-writer
Depends: openoffice.org-core-experimental (>> 2.0.3), libc6 (>= 2.4-1), libgcc1 (>= 1:4.1.1-11ubuntu1), libicu34, libstdc++6 (>= 4.1.1-11ubuntu1), libstlport4.6c2, libwpd8c2a, zlib1g (>= 1:1.2.1)
Recommends: java-gcj-compat | j2re1.4 | java2-runtime
Conflicts: openoffice.org-debian-files, openoffice.org-writer, openoffice.org2-writer-experimental, openoffice.org2-writer
Filename: pool/universe/o/openoffice.org/openoffice.org-writer-experimental_2.0.3-6ubuntu1_amd64.deb
Size: 5958196
MD5sum: c9e9c7366957c174b1cd4ecaac610225
Description: OpenOffice.org office suite - word processor (experimental)
 OpenOffice.org is a full-featured office productivity suite that provides
 a near drop-in replacement for Microsoft(R) Office.
 .
 This package contains the the wordprocessor component for OpenOffice.org,
 a full-featured office productivity suite that provides a near drop-in
 replacement for Microsoft(R) Office.
Bugs: mailto:<email address hidden>
Origin: Ubuntu

Tried to save a Microsoft Word .doc file and it crashed. On the console it left the following message.
jamie@doomguy:~/COIT12170_Data_Comms$ *** stack smashing detected ***: /usr/lib/openoffice/program/soffice.bin terminated

Revision history for this message
Kees Cook (kees) wrote :

Looks like this compile of OO.o may not be safe with the new GCC stack protections. I can install and run OO.o from the "openoffice.org-writer" package on amd64. Does that work for you?

Revision history for this message
Martin Pitt (pitti) wrote :

Yet another duplicate for #58508

Changed in openoffice.org:
status: Unconfirmed → In Progress
Revision history for this message
Matthias Klose (doko) wrote :

OOo is built with stack-protection turned off. the 2.0.4 are built natively on amd64.

Changed in openoffice.org:
assignee: nobody → doko
status: In Progress → Fix Released
Revision history for this message
Yagisan (yagisan) wrote :

While that works around the issue, the fact that SSP was triggered indicates there is a buffer overflow somewhere that should be fixed.

Revision history for this message
Matt Zimmerman (mdz) wrote : Re: [Bug 61742] Re: Crashes with *** stack smashing detected *** message

On Fri, Sep 22, 2006 at 02:30:34PM -0000, Yagisan wrote:
> *** This bug is a duplicate of bug 58508 ***
>
> While that works around the issue, the fact that SSP was triggered
> indicates there is a buffer overflow somewhere that should be fixed.

Is this certain, or are false positives possible?

--
 - mdz

Revision history for this message
Yagisan (yagisan) wrote :

ssp is triggered when the function canary is overwritten, and as it was triggered is is very much unlikely to be a false positive. Hence my initial flagging of this as a security bug.

To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.