stack-buffer-overflow in format_options at genpstricks.c:1756
Xfig is a diagramming tool
Brought to you by:
tklxfiguser
Hi,
I found a stack-buffer-overflow in format_options at genpstricks.c:1756
fig2dev Version 3.2.7b
commit ca48ccc90bd3e7801a63cf9a541f292b28ed1260
Please run following command to reproduce it,
fig2dev -L pstricks $PoC
ASAN
==16398==ERROR: AddressSanitizer: stack-buffer-overflow on address 0x7ffde3b52d70 at pc 0x0000004482fa bp 0x7ffde3b52ac0 sp 0x7ffde3b52270
WRITE of size 258 at 0x7ffde3b52d70 thread T0
#0 0x4482f9 in vsprintf (/home/tmp/fig2dev+0x4482f9)
#1 0x448626 in __interceptor_sprintf (/home/tmp/fig2dev+0x448626)
#2 0x8110ff in format_options /home/tmp/mcj-fig2dev/fig2dev/dev/genpstricks.c:1756:7
#3 0x8051e0 in genpstrx_line /home/tmp/mcj-fig2dev/fig2dev/dev/genpstricks.c:2233:5
#4 0x549d5b in gendev_objects /home/tmp/mcj-fig2dev/fig2dev/fig2dev.c:1007:6
#5 0x549d5b in main /home/tmp/mcj-fig2dev/fig2dev/fig2dev.c:484
#6 0x7f8eae311b96 in __libc_start_main /build/glibc-OTsEL5/glibc-2.27/csu/../csu/libc-start.c:310
#7 0x41b469 in _start (/home/tmp/fig2dev+0x41b469)
Address 0x7ffde3b52d70 is located in stack of thread T0 at offset 432 in frame
#0 0x80ddbf in format_options /home/tmp/mcj-fig2dev/fig2dev/dev/genpstricks.c:1704
This frame has 6 object(s):
[32, 132) 'rn.i' (line 1100)
[176, 432) 'tmps' (line 1705)
[496, 752) 'tmps_alt' (line 1705) <== Memory access at offset 432 partially underflows this variable
[816, 1072) 'tmpc' (line 1705)
[1136, 1392) 'opts_sqrb' (line 1705)
[1456, 1712) 'opts_curb' (line 1705)
HINT: this may be a false positive if your program uses some custom stack unwind mechanism or swapcontext
(longjmp and C++ exceptions *are* supported)
SUMMARY: AddressSanitizer: stack-buffer-overflow (/home/tmp/fig2dev+0x4482f9) in vsprintf
Shadow bytes around the buggy address:
0x10003c762550: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
0x10003c762560: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
0x10003c762570: 00 00 00 00 00 00 00 00 f1 f1 f1 f1 f8 f8 f8 f8
0x10003c762580: f8 f8 f8 f8 f8 f8 f8 f8 f8 f2 f2 f2 f2 f2 00 00
0x10003c762590: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
=>0x10003c7625a0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00[f2]f2
0x10003c7625b0: f2 f2 f2 f2 f2 f2 00 00 00 00 00 00 00 00 00 00
0x10003c7625c0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
0x10003c7625d0: 00 00 00 00 00 00 f2 f2 f2 f2 f2 f2 f2 f2 00 00
0x10003c7625e0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
0x10003c7625f0: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 f2 f2
Shadow byte legend (one shadow byte represents 8 application bytes):
Addressable: 00
Partially addressable: 01 02 03 04 05 06 07
Heap left redzone: fa
Freed heap region: fd
Stack left redzone: f1
Stack mid redzone: f2
Stack right redzone: f3
Stack after return: f5
Stack use after scope: f8
Global redzone: f9
Global init order: f6
Poisoned by user: f7
Container overflow: fc
Array cookie: ac
Intra object redzone: bb
ASan internal: fe
Left alloca redzone: ca
Right alloca redzone: cb
==16398==ABORTING
Commit [d21a3a] fixes this issue.
Related
Commit: [d21a3a]