-
Notifications
You must be signed in to change notification settings - Fork 229
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
ERROR - Segmentation fault-TransformPaletteC<FileIO>::save #503
Comments
(gdb) bt |
(gdb) i r |
(gdb) x/8i $pc |
Warning: expected ".png", ".pnm" or ".pam" file name extension for input file, trying anyway... 0x60300000eea0 is located 16 bytes inside of 32-byte region [0x60300000ee90,0x60300000eeb0) previously allocated by thread T0 here: SUMMARY: AddressSanitizer: heap-use-after-free transform/palette_C.hpp:130 TransformPaletteC::process(ColorRanges const*, std::vector<Image, std::allocator > const&) |
CVE-2018-10972 has been assigned for this issue (not requested by me). |
@EnchantedJohn include sample PoC file to this issue e.g. inside zip file. |
@jonsneyers FLIF is marked for autoremoval from Debian testing on Sat 09 Jun 2018 as this is considered a grave security issue... |
Thanks,guys,I will close this issue. |
Err what @EnchantedJohn. Why did you close this? This is not fixed. |
What? The problem is still there on openSUSE Tumbleweed. If you don't plan on fixing this and the other security issues, please tell for I need to know how to proceed. |
@luigino I don't think that upstream has commented on this case. This should be reopened and fixed. I personally don't have skills to create a PR. |
@fgeek right, sorry. |
@jonsneyers If these issues (#503, #501, #509, #505, #504, #502 and others from @EnchantedJohn, plus #498) can't be addressed in the short term, I'll have to pull FLIF from Debian for the moment. The bugs are grave, and without fixing them the package won't make it to Debian testing (or stable) anyway. This doesn't mean the package can't be made part of Debian again in the future, after bringing it in better shape. I prefer to pull it before any other package sets a dependency on it. |
@paride I don't think the developer cares. |
The third Error is also Segmentation fault .I also use AFL tools
The error is :
Starting program: /home/lx/5_7/flif/flif/src/flif -e crashes/id:000010,sig:11,src:000110,op:havoc,rep:2 test5.flif --overwrite
Warning: expected ".png", ".pnm" or ".pam" file name extension for input file, trying anyway...
Program received signal SIGSEGV, Segmentation fault.
TransformPaletteC::save (this=, srcRanges=0xd05eb0, rac=...) at transform/palette_C.hpp:156
156 coder.write_int(0, srcRanges->max(p)-min-remaining, CPalette_vector[p][i]-min);
The text was updated successfully, but these errors were encountered: