Menu

#148 [BUG] two null pointers dereference in put_patternarc, genpict2e.c:2395 and 2400, diffferent from #145

fig2dev
closed
nobody
None
2023-08-25
2022-08-03
Han Zheng
No

Hello, I was testing my fuzzer and find two null pointer dereferences in fig2dev, which is different from #145. Here are the details

short describe

There is a null pointer dereference in fig2dev, in function put_patternarc, genpict2e.c:2400 and 2395.

environment

fig2dev latest commit 6678ad8cbf99fdbd9e0929fb26501d1f01f36698,
gcc 11.2.0
Ubuntu 22.04

step to reproduce

compile with CC="gcc -g -fsanitize=address", run ./fig2dev -L pict2e $POC

ASan Log

\unitlength4144sp% 4143.7 sp = (1/472.44) cm
\begin{picture}(91001333,256143194)%(0,0)
\ifx\allinethickness\undefined
  \def\XFigeepicthickness#1{\relax}
\else
  \let\XFigeepicthickness\allinethickness
\fi
{\color[rgb]{0,0.69,0.69}
\polygon*(5265,256141871)(5265,256138721)(7965,256137371)(7965,256140521)
\color{black}
\linethickness{7.5\unitlength}\XFigeepicthickness{7.5\unitlength}%\thinlines
\polygon(5265,256141871)(5265,256138721)(7965,256137371)(7965,256140521)
\color[rgb]{0.9,0.9,1}
\polygon*(2521,256139231)(2521,256136081)(5221,256134731)(5221,256137881)
\color{black}
\polygon(2521,256139231)(2521,256136081)(5221,256134731)(5221,256137881)
\color{white}
\moveto(6525,256140296)\curveto(6754,256140296)(6940,256140014)(6940,256139666)\curveto(6940,256139318)(6754,256139036)(6525,256139036)
\curveto(6296,256139036)(6110,256139318)(6110,256139666)\curveto(6110,256140014)(6296,256140296)(6525,256140296)\closepath\fillpath
\color{black}
\moveto(6525,256140296)\curveto(6754,256140296)(6940,256140014)(6940,256139666)\curveto(6940,256139318)(6754,256139036)(6525,256139036)
\curveto(6296,256139036)(6110,256139318)(6110,256139666)\curveto(6110,256140014)(6296,256140296)(6525,256140296)\closepath\strokepath
\put(6121,256137656){\makebox(0,0)[lb]{\smash{\fontsize{24}{28.8}\usefont{T1}{pnc}{m}{it}E}}}
\put(6346,256137551){\makebox(0,0)[lb]{\smash{\fontsize{16}{19.2}\usefont{T1}{pnc}{m}{it}x}}}
\color{red}
\polygon*(6693,256139024)(6751,256138999)(6812,256139013)
\linethickness{15\unitlength}\XFigeepicthickness{15\unitlength}%\thicklines
\polygon(6693,256139024)(6751,256138999)(6812,256139013)
\polygon*(7080,256139886)(7020,256139884)(6960,256139881)
\polygon(7080,256139886)(7020,256139884)(6960,256139881)
\circlearc[1]{47}{256139609}{6855}{-4.967}{2.195}\strokepath
\color{black}
\linethickness{30\unitlength}\XFigeepicthickness{30\unitlength}%
\Line(126,256136966)(1101,256134369)
\polygon*(1021,256134323)(1106,256134355)(1190,256134387)
\polygon(1021,256134323)(1106,256134355)(1190,256134387)
\linethickness{15\unitlength}\XFigeepicthickness{15\unitlength}%\thicklines
\multiput(8551,256141526)(180,-2.3){5}{\line(90,-1){90}}
\Line(9451,256141514)(9472,256141514)
\polygon(9478,256141454)(9719,256141511)(9479,256141574)
\multiput(8491,256141526)(0,180){5}{\line(0,1){90}}
\Line(8491,256142426)(8491,256142447)
\polygon(8551,256142454)(8491,256142694)(8431,256142454)
\linethickness{30\unitlength}\XFigeepicthickness{30\unitlength}%
\multiput(7684,256140668)(-175.2,-164){5}{\line(-44,-41){88}}
\multiput(4936,256138031)(-172.8,-166.6){6}{\line(-86,-83){86}}
\Line(3899,256137031)(3868,256137001)
\Line(8551,256141541)(7703,256140694)
\put(9346,256141166){\makebox(0,0)[lb]{\smash{\fontsize{24}{28.8}\usefont{T1}{pnc}{m}{it}x}}}
\put(8686,256142411){\makebox(0,0)[lb]{\smash{\fontsize{24}{28.8}\usefont{T1}{pnc}{m}{it}y}}}
\put(1036,256134671){\makebox(0,0)[lb]{\smash{\fontsize{24}{28.8}\usefont{T1}{pnc}{m}{it}z}}}
\put(4486,256139306){\makebox(0,0)[lb]{\smash{\fontsize{24}{28.8}\usefont{T1}{pnc}{m}{it}E}}}
\put(62,256142826){\makebox(0,0)[lb]{\smash{\fontsize{16}{19.2}\usefont{T1}{pnc}{m}{it}1455 5355 8115 Polariser}}}
\put(7966,256142351){\makebox(0,0)[lb]{\smash{\fontsize{24}{28.8}\usefont{T1}{pnc}{m}{it}E}}}
\put(8206,256142276){\makebox(0,0)[lb]{\smash{\fontsize{16}{19.2}\usefont{T1}{pnc}{m}{it}y}}}
\put(1666,256136576){\makebox(0,0)[lb]{\smash{\fontsize{24}{28.8}\usefont{T1}{pnc}{m}{it}E}}}
\put(1921,256136516){\makebox(0,0)[lb]{\smash{\fontsize{16}{19.2}\usefont{T1}{pnc}{m}{it}y}}}
\Line(6886,256139921)(4951,256138031)
\circlearc[1]{79000046}{244139651}{5.02161e+07}{89.064087}{-153.288684}\closepath\fillpath
AddressSanitizer:DEADLYSIGNAL
=================================================================
==2412370==ERROR: AddressSanitizer: SEGV on unknown address 0x000000000000 (pc 0x55e78a5f7d4a bp 0x60c000000100 sp 0x7ffecacdbe20 T0)
==2412370==The signal is caused by a READ memory access.
==2412370==Hint: address points to the zero page.
    #0 0x55e78a5f7d4a in put_patternarc /validate/mcj-fig2dev/fig2dev/dev/genpict2e.c:2400
    #1 0x55e78a5f9c6b in genpict2e_arc /validate/mcj-fig2dev/fig2dev/dev/genpict2e.c:2549
    #2 0x55e78a57adfb in gendev_objects /validate/mcj-fig2dev/fig2dev/fig2dev.c:1026
    #3 0x55e78a57adfb in main /validate/mcj-fig2dev/fig2dev/fig2dev.c:502
    #4 0x7f0a8c885d8f in __libc_start_call_main ../sysdeps/nptl/libc_start_call_main.h:58
    #5 0x7f0a8c885e3f in __libc_start_main_impl ../csu/libc-start.c:392
    #6 0x55e78a57b9a4 in _start (/validate/mcj-fig2dev/fig2dev/fig2dev+0x6e9a4)

AddressSanitizer can not provide additional info.
SUMMARY: AddressSanitizer: SEGV /validate/mcj-fig2dev/fig2dev/dev/genpict2e.c:2400 in put_patternarc
==2412370==ABORTING

POC

two of them are in the attachment

Credit

Han Zheng(NCNIPC of China, Hexhive)
Yin Li, Xiaotong Jiao (NCNIPC of China)

1 Attachments

Related

Tickets: #145

Discussion

  • tkl

    tkl - 2022-08-11
    • status: open --> pending
    • xfig / fig2dev: xfig --> fig2dev
     
  • tkl

    tkl - 2022-08-11

    Now, this is a beautiful bug. The underlying cause is the same as for ticket [#145]. For the pict2e output language, arcs are drawn by first generating a polyline from a spline which approximates a circle. Then the algorithm walks along the line until the angle covered by the arc is reached. Whether the final angle is reached is not done by computing the angle for each point, but by comparing one of the point coordinates with the sinus or cosinus of the final angle, multiplied with the radius. The first method would involve a call to atan2() or similar, the latter is one integer comparison. Now, the error was that under some circumstances the long coordinate was compared. Close to the horizontal or vertical axis this would give not only a glancing intersection, but could fail. The polyline approximating the circle varies by less than 1.5 promille around the true radius. However, for a circle larger than one inch, or 1200 Fig units, this would amount to a few Fig units and the comparison may fail. Fixed with commit [ed4d04]

     

    Related

    Tickets: #145
    Commit: [ed4d04]

  • Han Zheng

    Han Zheng - 2022-08-12

    Thanks for the quick fix & commit, in my test environment both #145 and #148 are fixed.

     
  • tkl

    tkl - 2022-08-25
    • Description has changed:

    Diff:

    --- old
    +++ new
    @@ -95,6 +95,6 @@
     two of them are in the attachment
    
     ### Credit 
    -Han Zheng, NCNIPC of China (nipc.org.cn), Hexhive(hexhive.epfl.ch)
    +Han Zheng(NCNIPC of China, Hexhive)
    +Yin Li, Xiaotong Jiao (NCNIPC of China)
    
    -
    
     
  • tkl

    tkl - 2023-08-25
    • status: pending --> closed
     

Log in to post a comment.