Bug 1095791

Summary: LibreOffice Draw crashes with invalid pointer
Product: [Fedora] Fedora Reporter: Valentin Villenave <valentin>
Component: libreofficeAssignee: Caolan McNamara <caolanm>
Status: CLOSED DUPLICATE QA Contact: Fedora Extras Quality Assurance <extras-qa>
Severity: high Docs Contact:
Priority: unspecified    
Version: 20CC: caolanm, dtardon, erack, ltinkl, mstahl, sbergman
Target Milestone: ---   
Target Release: ---   
Hardware: x86_64   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2014-05-09 08:14:25 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Attachments:
Description Flags
Memory map none

Description Valentin Villenave 2014-05-08 14:20:12 UTC
Created attachment 893639 [details]
Memory map

Greetings,


LibreOffice Draw 4.2.3.3-9.fc20 is unable to launch. (Writer works fine, though.)
Tested with both f20 stable and updates-testing as of today.


Steps to Reproduce:
1. Launch libreoffice, then select Draw or open an existing or new Draw document.
2. The program crashes immediately and leaves you back to prompt.


The error message is:
*** Error in `/usr/lib64/libreoffice/program/soffice.bin': munmap_chunk(): invalid pointer: 0x0000000001f80770 ***

Backtrace:
/lib64/libc.so.6(+0x75cff)[0x7f1830f7fcff]
/lib64/libc.so.6(+0x7bb27)[0x7f1830f85b27]
/usr/lib64/libreoffice/program/libsfxlo.so(_ZN14SfxObjectShellD1Ev+0x14b)[0x7f182edbb98b]
/usr/lib64/libreoffice/program/libsfxlo.so(_ZN14SfxObjectShellD0Ev+0x9)[0x7f182edbbd39]
/usr/lib64/libreoffice/program/libsfxlo.so(_ZN14SfxObjectShell5CloseEv+0x130)[0x7f182edbb150]
/usr/lib64/libreoffice/program/libsfxlo.so(_ZN14SfxObjectShellD2Ev+0x72)[0x7f182edbb432]
/usr/lib64/libreoffice/program/../program/libsdlo.so(_ZN2sd12DrawDocShellC2Emh12DocumentType+0xed)[0x7f180119ed6d]
/usr/lib64/libreoffice/program/../program/libsdlo.so(+0x2ed531)[0x7f18011a0531]
/usr/lib64/libreoffice/program/../program/libsdlo.so(+0x43fba4)[0x7f18012f2ba4]
/usr/lib64/libreoffice/program/libsfxlo.so(+0x37cf74)[0x7f182edf6f74]
/usr/lib64/libreoffice/program/libsfxlo.so(+0x37ccb5)[0x7f182edf6cb5]
/usr/lib64/libreoffice/program/../ure-link/lib/libuno_cppuhelpergcc3.so.3(+0x863d2)[0x7f182f88a3d2]
/usr/lib64/libreoffice/program/libsfxlo.so(+0x3f5418)[0x7f182ee6f418]
/usr/lib64/libreoffice/program/../program/libfwklo.so(+0x13140d)[0x7f1811a7940d]
/usr/lib64/libreoffice/program/../program/libfwklo.so(+0x131c78)[0x7f1811a79c78]
/usr/lib64/libreoffice/program/../program/libfwklo.so(+0xbdfd4)[0x7f1811a05fd4]
/usr/lib64/libreoffice/program/../program/libfwklo.so(+0xbee26)[0x7f1811a06e26]
/usr/lib64/libreoffice/program/libsfxlo.so(+0x20697e)[0x7f182ec8097e]
/usr/lib64/libreoffice/program/libvcllo.so(+0x40a4ec)[0x7f182cfe84ec]
/usr/lib64/libreoffice/program/libvcllo.so(_ZN17SalGenericDisplay21DispatchInternalEventEv+0x78)[0x7f182cfeefc8]
/usr/lib64/libreoffice/program/libvclplug_gtklo.so(+0x3729f)[0x7f181b03429f]
/usr/lib64/libreoffice/program/libvclplug_gtklo.so(+0x37311)[0x7f181b034311]
/lib64/libglib-2.0.so.0(g_main_context_dispatch+0x166)[0x7f182ba422a6]
/lib64/libglib-2.0.so.0(+0x49628)[0x7f182ba42628]
/lib64/libglib-2.0.so.0(g_main_context_iteration+0x2c)[0x7f182ba426dc]
/usr/lib64/libreoffice/program/libvclplug_gtklo.so(+0x37005)[0x7f181b034005]
/usr/lib64/libreoffice/program/libvcllo.so(_ZN11Application5YieldEv+0x52)[0x7f182ccfa082]
/usr/lib64/libreoffice/program/libvcllo.so(_ZN11Application7ExecuteEv+0x25)[0x7f182ccfa115]
/usr/lib64/libreoffice/program/libsofficeapp.so(+0x22e83)[0x7f18312ebe83]
/usr/lib64/libreoffice/program/libvcllo.so(+0x1237e1)[0x7f182cd017e1]
/usr/lib64/libreoffice/program/libvcllo.so(_Z6SVMainv+0x22)[0x7f182cd01812]
/usr/lib64/libreoffice/program/libsofficeapp.so(soffice_main+0x135)[0x7f1831310ca5]
/usr/lib64/libreoffice/program/soffice.bin[0x40071b]
/lib64/libc.so.6(__libc_start_main+0xf5)[0x7f1830f2bd65]
/usr/lib64/libreoffice/program/soffice.bin[0x400751]

Full memory map attached.

Comment 1 David Tardon 2014-05-09 08:14:25 UTC

*** This bug has been marked as a duplicate of bug 1071604 ***