Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Segfault with fuzzed file (oggflac) #483

Closed
tholin opened this issue Jan 1, 2015 · 2 comments
Closed

Segfault with fuzzed file (oggflac) #483

tholin opened this issue Jan 1, 2015 · 2 comments

Comments

@tholin
Copy link

@tholin tholin commented Jan 1, 2015

Parsing the following file with the tagreader example results in a segfault.
https://www.dropbox.com/s/1gjqpn6ljlno2p0/taglib_oggflac_segfault.oga

$ gdb --args ~/repository/taglib/build/examples/tagreader taglib_oggflac_segfault.oga 
GNU gdb (Gentoo 7.7.1 p1) 7.7.1
Copyright (C) 2014 Free Software Foundation, Inc.
License GPLv3+: GNU GPL version 3 or later <http://gnu.org/licenses/gpl.html>
This is free software: you are free to change and redistribute it.
There is NO WARRANTY, to the extent permitted by law.  Type "show copying"
and "show warranty" for details.
This GDB was configured as "x86_64-pc-linux-gnu".
Type "show configuration" for configuration details.
For bug reporting instructions, please see:
<http://bugs.gentoo.org/>.
Find the GDB manual and other documentation resources online at:
<http://www.gnu.org/software/gdb/documentation/>.
For help, type "help".
Type "apropos word" to search for commands related to "word"...
Reading symbols from /home/cocobo/repository/taglib/build/examples/tagreader...done.
(gdb) r
Starting program: /home/cocobo/repository/taglib/build/examples/tagreader taglib_oggflac_segfault.oga
warning: Could not load shared library symbols for linux-vdso.so.1.
Do you need "set solib-search-path" or "set sysroot"?
******************** "taglib_oggflac_segfault.oga" ********************

Program received signal SIGSEGV, Segmentation fault.
0x00007ffff7a0c9bc in TagLib::Ogg::FLAC::File::scan (this=0x617cd0)
    at /home/cocobo/repository/taglib/taglib/ogg/flac/oggflacfile.cpp:247
247       char blockType = header[0] & 0x7f;
(gdb) bt full
#0  0x00007ffff7a0c9bc in TagLib::Ogg::FLAC::File::scan (this=0x617cd0)
    at /home/cocobo/repository/taglib/taglib/ogg/flac/oggflacfile.cpp:247
        ipacket = 1
        overhead = 0
        metadataHeader = {_vptr.ByteVector = 0x7ffff7dce5f0 <vtable for TagLib::ByteVector+16>, 
          static null = {_vptr.ByteVector = 0x7ffff7dce5f0 <vtable for TagLib::ByteVector+16>, 
            static null = <same as static member of an already seen type>, d = 0x616b40}, 
          d = 0x6184a0}
        blockType = 90 'Z'
        lastBlock = 255
        length = 0
        header = {_vptr.ByteVector = 0x7ffff7dce5f0 <vtable for TagLib::ByteVector+16>, 
          static null = {_vptr.ByteVector = 0x7ffff7dce5f0 <vtable for TagLib::ByteVector+16>, 
            static null = <same as static member of an already seen type>, d = 0x616b40}, 
          d = 0x6194c0}
#1  0x00007ffff7a0baf4 in TagLib::Ogg::FLAC::File::read (this=0x617cd0, readProperties=true, 
    propertiesStyle=TagLib::AudioProperties::Average)
    at /home/cocobo/repository/taglib/taglib/ogg/flac/oggflacfile.cpp:164
No locals.
#2  0x00007ffff7a0aa45 in TagLib::Ogg::FLAC::File::File (this=0x617cd0, 
    file=0x7fffffffde7e "taglib_oggflac_segfault.oga", readProperties=true, 
    propertiesStyle=TagLib::AudioProperties::Average)
    at /home/cocobo/repository/taglib/taglib/ogg/flac/oggflacfile.cpp:77
No locals.
#3  0x00007ffff7b7aa8c in TagLib::FileRef::create (
    fileName=0x7fffffffde7e "taglib_oggflac_segfault.oga", readAudioProperties=true, 
    audioPropertiesStyle=TagLib::AudioProperties::Average)
    at /home/cocobo/repository/taglib/taglib/fileref.cpp:246
        file = 0x0
        it = 
        ext = {_vptr.String = 0x7ffff7dce4f0 <vtable for TagLib::String+16>, static null = {
            _vptr.String = 0x7ffff7dce4f0 <vtable for TagLib::String+16>, 
            static null = <same as static member of an already seen type>, 
            static WCharByteOrder = TagLib::String::UTF16LE, d = 0x616af0}, 
          static WCharByteOrder = TagLib::String::UTF16LE, d = 0x617db0}
#4  0x00007ffff7b77ad1 in TagLib::FileRef::FileRef (this=0x7fffffffd8d0, 
    fileName=0x7fffffffde7e "taglib_oggflac_segfault.oga", readAudioProperties=true, 
    audioPropertiesStyle=TagLib::AudioProperties::Average)
    at /home/cocobo/repository/taglib/taglib/fileref.cpp:83
No locals.
#5  0x00000000004048a7 in main (argc=2, argv=0x7fffffffda58)
    at /home/cocobo/repository/taglib/examples/tagreader.cpp:41
        f = {_vptr.FileRef = 0x7ffff7dd0610 <vtable for TagLib::FileRef+16>, d = 0x404792 <main+34>}
        i = 1
#6  0x00007ffff6c76dc5 in __libc_start_main () from /lib64/libc.so.6
No symbol table info available.
#7  0x00000000004046a9 in _start ()
No symbol table info available.
(gdb) list
242       //    ..
243       //    4 : VORBIS_COMMENT
244       //    ..
245       // <24> Length of metadata to follow
246
247       char blockType = header[0] & 0x7f;
248       bool lastBlock = (header[0] & 0x80) != 0;
249       uint length = header.toUInt(1, 3, true);
250       overhead += length;
251
(gdb) print header.size()
$1 = 0
@sbooth
Copy link
Contributor

@sbooth sbooth commented Jan 1, 2015

What is the preferred way to merge these changes in the taglib2 branch?

@TsudaKageyu
Copy link
Contributor

@TsudaKageyu TsudaKageyu commented Jan 1, 2015

I'm going to do it later on.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Linked pull requests

Successfully merging a pull request may close this issue.

3 participants
You can’t perform that action at this time.