Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Panic on attempt to subtract with overflow #34

Open
neosilky opened this issue Jun 22, 2018 · 0 comments

Comments

Projects
None yet
1 participant
@neosilky
Copy link

commented Jun 22, 2018

Found with honggfuzz.

extern crate obj;

use std::io::Cursor;

fn main() {
    let cursor = Cursor::new(b"\x70\x09\x2D\x31\x38");
    let _: Result<obj::Obj, obj::ObjError> = obj::load_obj(cursor);
}
thread 'main' panicked at 'attempt to subtract with overflow', /home/user/.cargo/git/checkouts/obj-rs-dfe6c4fd11f0b626/f37de06/src/raw/object.rs:40:9
stack backtrace:
   0: std::sys::unix::backtrace::tracing::imp::unwind_backtrace
             at libstd/sys/unix/backtrace/tracing/gcc_s.rs:49
   1: std::sys_common::backtrace::print
             at libstd/sys_common/backtrace.rs:71
             at libstd/sys_common/backtrace.rs:59
   2: std::panicking::default_hook::{{closure}}
             at libstd/panicking.rs:211
   3: std::panicking::default_hook
             at libstd/panicking.rs:227
   4: std::panicking::rust_panic_with_hook
             at libstd/panicking.rs:463
   5: std::panicking::begin_panic_fmt
             at libstd/panicking.rs:350
   6: rust_begin_unwind
             at libstd/panicking.rs:328
   7: core::panicking::panic_fmt
             at libcore/panicking.rs:71
   8: core::panicking::panic
             at libcore/panicking.rs:51
   9: obj::raw::object::parse_obj::{{closure}}
             at /home/user/.cargo/git/checkouts/obj-rs-dfe6c4fd11f0b626/f37de06/src/raw/object.rs:40
  10: obj::raw::lexer::lex
             at /home/user/.cargo/git/checkouts/obj-rs-dfe6c4fd11f0b626/f37de06/src/raw/lexer.rs:49
  11: obj::raw::object::parse_obj
             at /home/user/.cargo/git/checkouts/obj-rs-dfe6c4fd11f0b626/f37de06/src/raw/object.rs:66
  12: obj::load_obj
             at /home/user/.cargo/git/checkouts/obj-rs-dfe6c4fd11f0b626/f37de06/src/lib.rs:50
  13: obj_load::main::{{closure}}
             at /home/user/daniel/targets/common/src/lib.rs:392
             at fuzzer-honggfuzz/src/bin/obj_load.rs:8
  14: honggfuzz::fuzz
             at /home/user/.cargo/registry/src/github.com-1ecc6299db9ec823/honggfuzz-0.5.20/src/lib.rs:301
  15: obj_load::main
             at fuzzer-honggfuzz/src/bin/obj_load.rs:7
  16: std::rt::lang_start::{{closure}}
             at /checkout/src/libstd/rt.rs:74
  17: std::panicking::try::do_call
             at libstd/rt.rs:59
             at libstd/panicking.rs:310
  18: __rust_maybe_catch_panic
             at libpanic_unwind/lib.rs:105
  19: std::rt::lang_start_internal
             at libstd/panicking.rs:289
             at libstd/panic.rs:374
             at libstd/rt.rs:58
  20: std::rt::lang_start
             at /checkout/src/libstd/rt.rs:74
  21: main
  22: __libc_start_main
  23: _start
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
You can’t perform that action at this time.