oss-sec mailing list archives

Re: Crashes and memory safety bugs in dcraw


From: Agostino Sarubbo <ago () gentoo org>
Date: Fri, 23 Nov 2018 09:34:51 +0100

On venerdì 23 novembre 2018 09:22:17 CET Hanno Böck wrote:
Segfault / memory read on invalid address in crop_masked_pixels
==6511==ERROR: AddressSanitizer: SEGV on unknown address 0x7fa0aa2ad79e (pc
0x0000005992fe bp 0x7ffdd236bb50 sp 0x7ffdd236b9e0 T0) ==6511==The signal
is caused by a READ memory access.
    #0 0x5992fd in crop_masked_pixels /mnt/ram/dcraw/dcraw.c:3775:20
    #1 0x668a33 in main /mnt/ram/dcraw/dcraw.c:10406:7
    #2 0x7fa05f3264ca in __libc_start_main (/lib64/libc.so.6+0x234ca)
    #3 0x41c629 in _start (/mnt/ram/dcraw/a.out+0x41c629)

Invalid memory read in crop_masked_pixels
==6893==ERROR: AddressSanitizer: SEGV on unknown address 0x7f5514dad79e (pc
0x0000005992fe bp 0x7ffc83994ad0 sp 0x7ffc83994960 T0) ==6893==The signal
is caused by a READ memory access.
    #0 0x5992fd in crop_masked_pixels /mnt/ram/dcraw/dcraw.c:3775:20
    #1 0x668a33 in main /mnt/ram/dcraw/dcraw.c:10406:7
    #2 0x7f54c9df64ca in __libc_start_main (/lib64/libc.so.6+0x234ca)
    #3 0x41c629 in _start (/mnt/ram/dcraw/a.out+0x41c629)

Hi Hanno,

are the first and the third similar or I'm missing something?
TIA

-- 
Agostino Sarubbo
Gentoo Linux Developer

Current thread: