evince crashed with SIGSEGV in get_optional_content_items_sorted()
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
poppler (Ubuntu) |
Triaged
|
Medium
|
Unassigned |
Bug Description
evince crashes after an out of bounds write. Marking initially as a vuln because some memory is written.
#0 0x153d293e in get_optional_
at poppler-
#1 0x153d4014 in get_optional_
#2 _poppler_
#3 0x153d4207 in poppler_
#4 0x1474d601 in ?? () from /usr/lib/
#5 0x008b4673 in ev_document_
#6 0x00d5d95c in ?? ()
#7 0x00d60092 in ?? ()
#8 0x00d594ee in ?? ()
#9 0x00155e48 in g_cclosure_
#10 0x00139352 in g_closure_invoke () from /usr/lib/
#11 0x0014c048 in ?? () from /usr/lib/
#12 0x00154b29 in g_signal_
#13 0x00154cc2 in g_signal_emit () from /usr/lib/
#14 0x0013b0c1 in ?? () from /usr/lib/
#15 0x0013a3cf in ?? () from /usr/lib/
#16 0x0013d371 in g_object_notify () from /usr/lib/
#17 0x003857e9 in ev_document_
#18 0x00d547bd in ?? ()
#19 0x0015548c in g_cclosure_
#20 0x00139352 in g_closure_invoke () from /usr/lib/
#21 0x0014c048 in ?? () from /usr/lib/
#22 0x00154b29 in g_signal_
#23 0x00154cc2 in g_signal_emit () from /usr/lib/
#24 0x0038754c in ?? () from /usr/lib/
#25 0x00608451 in ?? () from /lib/libglib-
#26 0x0060cc08 in g_main_
#27 0x0060d3d0 in ?? () from /lib/libglib-
#28 0x0060da93 in g_main_loop_run () from /lib/libglib-
#29 0x00eb2a49 in gtk_main () from /usr/lib/
#30 0x00d62642 in main ()
ProblemType: Crash
DistroRelease: Ubuntu 11.04
Package: evince 2.32.0-0ubuntu10
ProcVersionSign
Uname: Linux 2.6.38-1-generic i686
Architecture: i386
Date: Sun Feb 27 22:54:50 2011
ExecutablePath: /usr/bin/evince
InstallationMedia: Ubuntu 11.04 "Natty Narwhal" - Alpha i386 (20110202)
ProcCmdline: evince sample2.pdf
ProcCmdline_: BOOT_IMAGE=
ProcEnviron:
SHELL=/bin/bash
LC_MESSAGES=
LANG=en_US.UTF-8
LANGUAGE=en_US:en
ProcVersionSign
SegvAnalysis:
Segfault happened at: 0x157ce93e <get_optional_
PC (0x157ce93e) ok
source "%eax" ok
destination "0x4(%edx)" (0x00000004) not located in a known VMA region (needed writable region)!
SegvReason: writing NULL VMA
Signal: 11
SourcePackage: evince
StacktraceTop:
get_optional_
get_optional_
_poppler_
poppler_
?? () from /usr/lib/
Title: evince crashed with SIGSEGV in get_optional_
UserGroups: adm admin cdrom dialout lpadmin plugdev sambashare
XsessionErrors: (nautilus:1366): GConf-CRITICAL **: gconf_value_free: assertion `value != NULL' failed
visibility: | private → public |
StacktraceTop: content_ items_sorted (ocg=0x2265ad30, parent=0x0, order=0x2264eb98) at poppler- document. cc:2095 content_ items (document= 0x22584200) at poppler- document. cc:2112 document_ get_layers (document= 0x22584200) at poppler- document. cc:2142 layers_ iter_new (document= 0x22584200) at poppler- document. cc:2230 layers_ has_layers (document= 0x224d8e88) at /build/ buildd/ evince- 2.32.0/ ./backend/ pdf/ev- poppler. cc:3177
get_optional_
get_optional_
_poppler_
poppler_
pdf_document_