Skip to content

An infinite loop #118

Closed
Closed
@bestshow

Description

@bestshow

On qpdf version 6.0.0, I discovered an infinite loop.

#qpdf $FILE -
==29487== stack-overflow on address 0x7fff5e6b1e38 (pc 0x0000005187d2 bp 0x7fff5e6b2680 sp 0x7fff5e6b1e10 T0)
    #0 0x5187d1 in operator new(unsigned long) /home/haojun/Downloads/llvm-clang/llvm/projects/compiler-rt/lib/asan/asan_new_delete.cc:82
    #1 0x65e604 in PointerHolder<QPDFObject>::PointerHolder(QPDFObject*, bool) /home/haojun/Downloads/qpdf-master/include/qpdf/PointerHolder.hh:75:17
    #2 0x65e604 in QPDFObjectHandle::QPDFObjectHandle(QPDF*, int, int) /home/haojun/Downloads/qpdf-master/libqpdf/QPDFObjectHandle.cc:45
    #3 0x65e604 in QPDFObjectHandle::newIndirect(QPDF*, int, int) /home/haojun/Downloads/qpdf-master/libqpdf/QPDFObjectHandle.cc:1093
    #4 0x5c27bf in QPDFObjectHandle::Factory::newIndirect(QPDF*, int, int) /home/haojun/Downloads/qpdf-master/include/qpdf/QPDFObjectHandle.hh:518:13
    #5 0x5c27bf in QPDF::getObjectByID(int, int) /home/haojun/Downloads/qpdf-master/libqpdf/QPDF.cc:1625
    #6 0x5c27bf in QPDF::resolveObjectsInStream(int) /home/haojun/Downloads/qpdf-master/libqpdf/QPDF.cc:1499
    #7 0x5c13b6 in QPDF::resolve(int, int) /home/haojun/Downloads/qpdf-master/libqpdf/QPDF.cc:1480:6
    #8 0x61e6c1 in QPDF::Resolver::resolve(QPDF*, int, int) /home/haojun/Downloads/qpdf-master/include/qpdf/QPDF.hh:520:19
    #9 0x61e6c1 in QPDFObjectHandle::dereference() /home/haojun/Downloads/qpdf-master/libqpdf/QPDFObjectHandle.cc:1520
    #10 0x621e00 in QPDFObjectHandle::isStream() /home/haojun/Downloads/qpdf-master/libqpdf/QPDFObjectHandle.cc:226:5
    #11 0x5c27ce in QPDF::resolveObjectsInStream(int) /home/haojun/Downloads/qpdf-master/libqpdf/QPDF.cc:1500:22
    #12 0x5c13b6 in QPDF::resolve(int, int) /home/haojun/Downloads/qpdf-master/libqpdf/QPDF.cc:1480:6
    #13 0x61e6c1 in QPDF::Resolver::resolve(QPDF*, int, int) /home/haojun/Downloads/qpdf-master/include/qpdf/QPDF.hh:520:19
    #14 0x61e6c1 in QPDFObjectHandle::dereference() /home/haojun/Downloads/qpdf-master/libqpdf/QPDFObjectHandle.cc:1520
    #15 0x621e00 in QPDFObjectHandle::isStream() /home/haojun/Downloads/qpdf-master/libqpdf/QPDFObjectHandle.cc:226:5
    #16 0x5c27ce in QPDF::resolveObjectsInStream(int) /home/haojun/Downloads/qpdf-master/libqpdf/QPDF.cc:1500:22
    #17 0x5c13b6 in QPDF::resolve(int, int) /home/haojun/Downloads/qpdf-master/libqpdf/QPDF.cc:1480:6
    #18 0x61e6c1 in QPDF::Resolver::resolve(QPDF*, int, int) /home/haojun/Downloads/qpdf-master/include/qpdf/QPDF.hh:520:19
    #19 0x61e6c1 in QPDFObjectHandle::dereference() /home/haojun/Downloads/qpdf-master/libqpdf/QPDFObjectHandle.cc:1520
    #20 0x621e00 in QPDFObjectHandle::isStream() /home/haojun/Downloads/qpdf-master/libqpdf/QPDFObjectHandle.cc:226:5
    ......

testcase : https://github.com/bestshow/p0cs/blob/master/qpdf-infiniteloop_2
Credit : ADLab of Venustech

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions