Login
[x]
Log in using an account from:
Fedora Account System
Red Hat Associate
Red Hat Customer
Or login using a Red Hat Bugzilla account
Forgot Password
Login:
Hide Forgot
Create an Account
Red Hat Bugzilla – Attachment 918910 Details for
Bug 1120925
lynx crashes due to use after free in scan_cookie_sublist()
[?]
New
Simple Search
Advanced Search
My Links
Browse
Requests
Reports
Current State
Search
Tabular reports
Graphical reports
Duplicates
Other Reports
User Changes
Plotly Reports
Bug Status
Bug Severity
Non-Defaults
|
Product Dashboard
Help
Page Help!
Bug Writing Guidelines
What's new
Browser Support Policy
5.0.4.rh83 Release notes
FAQ
Guides index
User guide
Web Services
Contact
Legal
This site requires JavaScript to be enabled to function correctly, please enable it.
File: backtrace
backtrace (text/plain), 12.12 KB, created by
Hin-Tak Leung
on 2014-07-18 02:08:41 UTC
(
hide
)
Description:
File: backtrace
Filename:
MIME Type:
Creator:
Hin-Tak Leung
Created:
2014-07-18 02:08:41 UTC
Size:
12.12 KB
patch
obsolete
>[New LWP 11168] >[Thread debugging using libthread_db enabled] >Using host libthread_db library "/lib64/libthread_db.so.1". >Core was generated by `lynx '. >Program terminated with signal SIGABRT, Aborted. >#0 0x0000003fa8e35c39 in __GI_raise (sig=sig@entry=6) at ../nptl/sysdeps/unix/sysv/linux/raise.c:56 >56 return INLINE_SYSCALL (tgkill, 3, pid, selftid, sig); > >Thread 1 (Thread 0x7f561159e840 (LWP 11168)): >#0 0x0000003fa8e35c39 in __GI_raise (sig=sig@entry=6) at ../nptl/sysdeps/unix/sysv/linux/raise.c:56 > resultvar = 0 > pid = 11168 > selftid = 11168 >#1 0x0000003fa8e37348 in __GI_abort () at abort.c:89 > save_stage = 2 > act = {__sigaction_handler = {sa_handler = 0x3fa91baa00 <_IO_stdfile_2_lock>, sa_sigaction = 0x3fa91baa00 <_IO_stdfile_2_lock>}, sa_mask = {__val = {5108824, 0, 51, 273420095936, 5108824, 51, 273416680479, 0, 273420095936, 1, 51, 51, 35398128, 140736003718144, 273416638381, 0}}, sa_flags = 11, sa_restorer = 0x2218180} > sigs = {__val = {32, 0 <repeats 15 times>}} >#2 0x0000000000434ee8 in FatalProblem (sig=11) at LYMain.c:4520 >No locals. >#3 <signal handler called> >No locals. >#4 scan_cookie_sublist (secure=0, header=0x22757a0 "__cfduid=d521b4c641a5306b384b3a2557b23fcad1404846514689; country_code=NL", sublist=0x2133cc0, port=80, path=0x2233a50 "", hostname=0x2218180 "") at LYCookie.c:726 > hl = 0x9d9d9d9d9d9d9d9d > co = <optimized out> > now = 1404847010 > crlftab = "\r\n\t\000\000\000\000" >#5 LYAddCookieHeader (hostname=hostname@entry=0x2218180 "", path=path@entry=0x2233a50 "", port=80, secure=secure@entry=0) at LYCookie.c:1886 > header = <optimized out> > hl = <optimized out> > next = 0x0 > de = <optimized out> >#6 0x00000000004a1828 in HTLoadHTTP (arg=<optimized out>, anAnchor=anAnchor@entry=0x221e850, format_out=format_out@entry=0x1dc0070, sink=sink@entry=0x0) at ../../../WWW/Library/Implementation/HTTP.c:1350 > abspath = 0x2233a50 "" > docname = 0x224a6e0 "" > colon = <optimized out> > portnumber = 80 > auth = <optimized out> > cookie = 0x0 > hostname = 0x2218180 "" > secure = 0 '\000' > n = 35576144 > i = <optimized out> > host = <optimized out> > empty = "" > s = 3 > url = <optimized out> > command = 0x22d6890 > eol = 0x0 > start_of_data = <optimized out> > status = <optimized out> > bytes_already_read = <optimized out> > crlf = "\r\n" > target = 0x0 > format_in = <optimized out> > do_head = 0 '\000' > do_post = 0 '\000' > METHOD = 0x4f9411 "GET" > line_buffer = 0x0 > line_kept_clean = 0x0 > extensions = 1 '\001' > linebuf = 0x22617e0 ", text/sgml" > temp = "\000\000\000\000\000\000\000\000P\372\336\001", '\000' <repeats 12 times>, "\240\347\336\001", '\000' <repeats 12 times>, "\360\344\336\001\000\000\000\000\200B\202\247\377\177\000\000pB\202\247\377\177\000\000\r\223\344\250?\000\000\000\037\376P\000\000\000\000" > first_Accept = <optimized out> > show_401 = 0 '\000' > show_407 = 0 '\000' > auth_proxy = <optimized out> > length = 0 > rawlength = <optimized out> > rv = <optimized out> > server_status = 0 > doing_redirect = 0 '\000' > already_retrying = <optimized out> > len = <optimized out> > SSLerror = <optimized out> > do_connect = <optimized out> > did_connect = <optimized out> > connect_url = 0x0 > connect_host = 0x0 > handle = 0x0 > peer_cert = <optimized out> > ssl_dn = "\031\376P\000\000\000\000\000\261\205\344\250?\000\000\000\220\004\353\001\000\000\000\000\000\000\000\000\377\177\000\000\000\025\000\000\000\000\000\000 \000\000\000\000\000\000\000\320B\202\247\377\177\000\000\300B\202\247\377\177\000\000\r\223\344\250?\000\000\000*\376P\000\000\000\000\000(\376P\000\000\000\000\000\261\205\344\250?\000\000\000\260=\202\247\377\177\000\000\000B\223\331\242\345\352q@=\202\247\377\177\000\000/", '\000' <repeats 27 times>, "\377\177\000\000h", '\000' <repeats 15 times>, "@>\202\247\377\177\000\000\000>\202\247\377\177\000\000\004\000\000\000://w\000\000\000\000icka"... > cert_host = <optimized out> > ssl_host = <optimized out> > p = <optimized out> > msg = 0x0 > status_sslcertcheck = <optimized out> > ssl_dn_start = <optimized out> > ssl_all_cns = 0x0 > try_tls = 1 '\001' >#7 0x000000000049e3b6 in HTLoad (sink=<optimized out>, format_out=0x1dc0070, anchor=0x221e850, addr=<optimized out>) at ../../../WWW/Library/Implementation/HTAccess.c:706 > p = <optimized out> > status = <optimized out> >#8 HTLoadDocument (full_address=<optimized out>, anchor=0x221e850, format_out=0x1dc0070, sink=<optimized out>) at ../../../WWW/Library/Implementation/HTAccess.c:939 > status = 4847792 > text = 0x0 > address_to_load = <optimized out> > cp = 0x0 > ForcingNoCache = <optimized out> >#9 0x000000000049f108 in HTLoadAbsolute (docaddr=docaddr@entry=0x7fffa78245d0) at ../../../WWW/Library/Implementation/HTAccess.c:1121 >No locals. >#10 0x0000000000432020 in getfile (doc=doc@entry=0x76d6c0 <newdoc>, target=target@entry=0x7fffa78246c4) at LYGetFile.c:806 > url_type = <optimized out> > pound = <optimized out> > cp = <optimized out> > temp = 0x0 > WWWDoc = {address = 0x226e020 "", post_data = 0x0, post_content_type = 0x0, bookmark = 0x0, isHEAD = 0 '\000', safe = 0 '\000'} >#11 0x00000000004383a1 in mainloop () at LYMainLoop.c:5853 > c = 10 > real_c = 10 > old_c = 0 > pending_form_c = -1 > cmd = 39 > real_cmd = 39 > getresult = <optimized out> > arrowup = 0 > show_help = 0 > user_input_buffer = 0x1dc0610 > cshelpfile = 0x0 > first_file = 0 '\000' > popped_doc = 0 '\000' > refresh_screen = 0 '\000' > force_load = 0 '\000' > try_internal = 0 '\000' > crawl_ok = 0 '\000' > vi_keys_flag = 0 '\000' > emacs_keys_flag = 0 '\000' > trace_mode_flag = 0 '\000' > forced_HTML_mode = 0 '\000' > cfile = " \317\331\001\000\000\000\000\216\002\004\002\000\000\000\000\300H\202\247\377\177\000\000@\002\004\002\000\000\000\000 \317\331\001\000\000\000\000\005\000\000\000\000\000\000\000\v\000\000\000\000\000\000\000\252\b\343\250?\000\000\000en_GB.UTF-8\000?\000\000\000\020\377\347\250?\000\000\000\067\a\343\250?\000\000\000LC_MESSAGES/lynx.mo\000\377\177\000\000\000\000\000\000\000\000\000" > cfp = <optimized out> > cp = 0x2074770 "" > ch = 0 > recall = NORECALL > URLTotal = 0 > URLNum = 0 > FirstURLRecall = 1 '\001' > temp = 0x0 > ForcePush = <optimized out> > override_LYresubmit_posts = 0 '\000' > newdoc_link_is_absolute = 0 '\000' > curlink_is_editable = <optimized out> > use_last_tfpos = <optimized out> > len = <optimized out> > i = <optimized out> > follow_col = -1 > key_count = 1 > last_key = 10 > tmpNewline = -1 >#12 0x000000000040cf02 in main (argc=<optimized out>, argv=0x7fffa7824cc8) at LYMain.c:2238 > i = 2 > status = 0 > temp = 0x0 > ccp = <optimized out> > cp = <optimized out> > fp = <optimized out> > dir_info = {st_dev = 64769, st_ino = 4628481, st_nlink = 394, st_mode = 16877, st_uid = 500, st_gid = 500, __pad0 = 0, st_rdev = 0, st_size = 32768, st_blksize = 4096, st_blocks = 72, st_atim = {tv_sec = 1404787040, tv_nsec = 958124695}, st_mtim = {tv_sec = 1404840166, tv_nsec = 45607267}, st_ctim = {tv_sec = 1404840166, tv_nsec = 45607267}, __unused = {0, 0, 0}} > filename = "/home/Hin-Tak/.lynxsig\000et-runtime\000\002\000\000\000\000\000\001\000\000\000\000\000\000\000\060J\202\247\377\177\000\000\000\000\000\000\000\000\000\000[\000\000\000n", '\000' <repeats 19 times>, "w\000\000\000|\000\000\000/J\202\247\377\177\000\000\070N\202\247\377\177\000\000\262]\202\247\377\177\000\000\340\021\350\250?\000\000\000\250iZ\021V\177\000\000\000\000\000\000\000\000\000\000\220iZ\021V\177\000\000\000\000\340\250?", '\000' <repeats 11 times>, "`\207\033\251?\000\000\000\020\000\000\000\000\000\000\000\310L\202\247\377\177\000\000\340L\202\247\377\177\000\000"... > LYGetStdinArgs = <optimized out> >From To Syms Read Shared Object Library >0x0000003fa9e02210 0x0000003fa9e0e930 Yes /usr/lib64/libz.so.1 >0x0000003fb8608660 0x0000003fb862fb1c Yes /usr/lib64/libncursesw.so.5 >0x0000003fba40ce40 0x0000003fba418ba8 Yes /usr/lib64/libtinfo.so.5 >0x0000003309a183c0 0x0000003309a52400 Yes /usr/lib64/libssl.so.10 >0x0000003f7f469c40 0x0000003f7f55a4f8 Yes /usr/lib64/libcrypto.so.10 >0x0000003fa9600ed0 0x0000003fa96019d0 Yes /usr/lib64/libdl.so.2 >0x0000003fa8e1f560 0x0000003fa8f60bb4 Yes /usr/lib64/libc.so.6 >0x0000003308a0bd10 0x0000003308a3bdf4 Yes /usr/lib64/libgssapi_krb5.so.2 >0x00000033092251a0 0x000000330928775c Yes /usr/lib64/libkrb5.so.3 >0x0000003fafa01570 0x0000003fafa02154 Yes /usr/lib64/libcom_err.so.2 >0x00000033096048b0 0x00000033096247d8 Yes /usr/lib64/libk5crypto.so.3 >0x0000003fa8600b10 0x0000003fa8619c70 Yes /lib64/ld-linux-x86-64.so.2 >0x0000003308e03620 0x0000003308e09f8c Yes /usr/lib64/libkrb5support.so.0 >0x0000003fb0601570 0x0000003fb0602194 Yes /usr/lib64/libkeyutils.so.1 >0x0000003fab603a40 0x0000003fab6127dc Yes /usr/lib64/libresolv.so.2 >0x0000003fa9a059f0 0x0000003fa9a11614 Yes /usr/lib64/libpthread.so.0 >0x00000033086064a0 0x0000003308618fe4 Yes /usr/lib64/libselinux.so.1 >0x0000003308201770 0x000000330824b8e8 Yes /usr/lib64/libpcre.so.1 >0x000000337a8030e0 0x000000337a819050 Yes /usr/lib64/liblzma.so.5 >$1 = 0x0 >No symbol "__glib_assert_msg" in current context. >rax 0x0 0 >rbx 0xb 11 >rcx 0xffffffffffffffff -1 >rdx 0x6 6 >rsi 0x2ba0 11168 >rdi 0x2ba0 11168 >rbp 0x2218180 0x2218180 >rsp 0x7fffa7823538 0x7fffa7823538 >r8 0x7f561159e840 140007635019840 >r9 0x206874697720676e 2335244403110602606 >r10 0x8 8 >r11 0x206 518 >r12 0x0 0 >r13 0x204c130 33866032 >r14 0x21c21f0 35398128 >r15 0x7fffa7823c00 140736003718144 >rip 0x3fa8e35c39 0x3fa8e35c39 <__GI_raise+57> >eflags 0x206 [ PF IF ] >cs 0x33 51 >ss 0x2b 43 >ds 0x0 0 >es 0x0 0 >fs 0x0 0 >gs 0x0 0 >Dump of assembler code for function __GI_raise: > 0x0000003fa8e35c00 <+0>: mov %fs:0x2d4,%eax > 0x0000003fa8e35c08 <+8>: mov %eax,%ecx > 0x0000003fa8e35c0a <+10>: mov %fs:0x2d0,%esi > 0x0000003fa8e35c12 <+18>: test %esi,%esi > 0x0000003fa8e35c14 <+20>: jne 0x3fa8e35c48 <__GI_raise+72> > 0x0000003fa8e35c16 <+22>: mov $0xba,%eax > 0x0000003fa8e35c1b <+27>: syscall > 0x0000003fa8e35c1d <+29>: mov %eax,%ecx > 0x0000003fa8e35c1f <+31>: mov %eax,%fs:0x2d0 > 0x0000003fa8e35c27 <+39>: mov %eax,%esi > 0x0000003fa8e35c29 <+41>: movslq %edi,%rdx > 0x0000003fa8e35c2c <+44>: movslq %esi,%rsi > 0x0000003fa8e35c2f <+47>: movslq %ecx,%rdi > 0x0000003fa8e35c32 <+50>: mov $0xea,%eax > 0x0000003fa8e35c37 <+55>: syscall >=> 0x0000003fa8e35c39 <+57>: cmp $0xfffffffffffff000,%rax > 0x0000003fa8e35c3f <+63>: ja 0x3fa8e35c5a <__GI_raise+90> > 0x0000003fa8e35c41 <+65>: repz retq > 0x0000003fa8e35c43 <+67>: nopl 0x0(%rax,%rax,1) > 0x0000003fa8e35c48 <+72>: test %eax,%eax > 0x0000003fa8e35c4a <+74>: jg 0x3fa8e35c29 <__GI_raise+41> > 0x0000003fa8e35c4c <+76>: mov %eax,%ecx > 0x0000003fa8e35c4e <+78>: neg %ecx > 0x0000003fa8e35c50 <+80>: test $0x7fffffff,%eax > 0x0000003fa8e35c55 <+85>: cmove %esi,%ecx > 0x0000003fa8e35c58 <+88>: jmp 0x3fa8e35c29 <__GI_raise+41> > 0x0000003fa8e35c5a <+90>: mov 0x3821d7(%rip),%rdx # 0x3fa91b7e38 > 0x0000003fa8e35c61 <+97>: neg %eax > 0x0000003fa8e35c63 <+99>: mov %eax,%fs:(%rdx) > 0x0000003fa8e35c66 <+102>: or $0xffffffffffffffff,%rax > 0x0000003fa8e35c6a <+106>: retq >End of assembler dump.
You cannot view the attachment while viewing its details because your browser does not support IFRAMEs.
View the attachment on a separate page
.
View Attachment As Raw
Actions:
View
Attachments on
bug 1120925
: 918910 |
918911
|
918912
|
918914
|
918916
|
918919
|
918921
|
918923
|
918925
|
918927