Package: xfpt
Version: 0.10-1
Severity: normal

Dear Maintainer,
running xfpt with the attached file leads to an invalid write, causing a 
segfault.

This is the output of Valgrind (valgrind xfpt -o /dev/null ./01_invalid_write):
[...]
==82== Invalid write of size 4
==82==    at 0x10BEA4: dot_process (dot.c:890)
==82==    by 0x10A4DC: main (xfpt.c:172)
==82==  Address 0x112000 is not stack'd, malloc'd or (recently) free'd
[...]

--
Regards,
Luca Borzacchiello

-- System Information:
Debian Release: 10.5
  APT prefers stable-updates
  APT policy: (500, 'stable-updates'), (500, 'stable')
Architecture: amd64 (x86_64)

Kernel: Linux 5.4.0-42-generic (SMP w/12 CPU cores)
Kernel taint flags: TAINT_PROPRIETARY_MODULE, TAINT_OOT_MODULE, 
TAINT_UNSIGNED_MODULE
Locale: LANG=C, LC_CTYPE=C.UTF-8 (charmap=UTF-8), LANGUAGE=C (charmap=UTF-8)
Shell: /bin/sh linked to /bin/dash
Init: unable to detect

Versions of packages xfpt depends on:
ii  libc6  2.28-10

xfpt recommends no packages.

xfpt suggests no packages.

-- no debconf information

Attachment: 01_invalid_write
Description: Binary data

Reply via email to