Package: unace-nonfree
Version: 2.5-7
Usertags: afl

unace crashes while trying to verify integrity of the attached file:

$ unace t crash.ace

UNACE v2.5     Copyright by ACE Compression Software       Mar 28 2012 15:55:30

processing archive /home/jwilk/crash.ace
Working: Creating listfile. Please wait.
Working: Reading archive. Please wait.                                    
Segmentation fault


If you rebuild the package from source, then (perhaps thanks to -fstack-protector-strong?) you get an error message explaining a bit what's going on:

*** stack smashing detected ***: /usr/bin/unace terminated


This bug was found using American fuzzy lop:
https://packages.debian.org/experimental/afl

-- System Information:
Debian Release: 8.0
 APT prefers unstable
 APT policy: (500, 'unstable'), (1, 'experimental')
Architecture: amd64 (x86_64)

Kernel: Linux 3.16.0-4-amd64 (SMP w/2 CPU cores)
Locale: LANG=C, LC_CTYPE=C (charmap=ANSI_X3.4-1968)
Shell: /bin/sh linked to /bin/dash
Init: systemd (via /run/systemd/system)

Versions of packages unace-nonfree depends on:
ii  libc6  2.19-13

--
Jakub Wilk

Attachment: crash.ace
Description: Binary data

Reply via email to