Bug 902089

Summary: [abrt] fontforge-20120731b-2.fc18: pcFree: Process /usr/bin/fontforge was killed by signal 11 (SIGSEGV)
Product: [Fedora] Fedora Reporter: igor.redhat <igor.redhat>
Component: fontforgeAssignee: Paul Flo Williams <paul>
Status: CLOSED CURRENTRELEASE QA Contact: Fedora Extras Quality Assurance <extras-qa>
Severity: unspecified Docs Contact:
Priority: unspecified    
Version: 18CC: fonts-bugs, kevin, paul, pnemade
Target Milestone: ---   
Target Release: ---   
Hardware: x86_64   
OS: Unspecified   
Whiteboard: abrt_hash:aa30462937c5fbcdc2be6128a30565436f7458d7
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2013-02-18 20:29:35 EST Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Attachments:
Description Flags
File: backtrace
none
File: cgroup
none
File: core_backtrace
none
File: dso_list
none
File: environ
none
File: limits
none
File: maps
none
File: open_fds
none
File: proc_pid_status
none
File: var_log_messages
none
pdf file with the font "Elli" that causes this coredump none

Description igor.redhat@gmail.com 2013-01-20 15:30:29 EST
Description of problem:
Open attached pdf file; when "Pick font" dialog shows up, choose font called "Elli" and press "OK". fontforge will crash - 100% reproducible.

Version-Release number of selected component:
fontforge-20120731b-2.fc18

Additional info:
backtrace_rating: 4
cmdline:        fontforge /tmp/tales-117.pdf
crash_function: pcFree
executable:     /usr/bin/fontforge
kernel:         3.7.2-201.fc18.x86_64
remote_result:  NOTFOUND
uid:            500

Truncated backtrace:
Thread no. 1 (6 frames)
 #1 pcFree at parsepdf.c:1983
 #2 _SFReadPdfFont at parsepdf.c:2096
 #3 _ReadSplineFont at splinefont.c:1086
 #4 ReadSplineFont at splinefont.c:1248
 #5 LoadSplineFont at splinefont.c:1321
 #6 ViewPostScriptFont at fontviewbase.c:1315
Comment 1 igor.redhat@gmail.com 2013-01-20 15:30:34 EST
Created attachment 683835 [details]
File: backtrace
Comment 2 igor.redhat@gmail.com 2013-01-20 15:30:36 EST
Created attachment 683836 [details]
File: cgroup
Comment 3 igor.redhat@gmail.com 2013-01-20 15:30:37 EST
Created attachment 683837 [details]
File: core_backtrace
Comment 4 igor.redhat@gmail.com 2013-01-20 15:30:39 EST
Created attachment 683838 [details]
File: dso_list
Comment 5 igor.redhat@gmail.com 2013-01-20 15:30:41 EST
Created attachment 683839 [details]
File: environ
Comment 6 igor.redhat@gmail.com 2013-01-20 15:30:43 EST
Created attachment 683840 [details]
File: limits
Comment 7 igor.redhat@gmail.com 2013-01-20 15:30:45 EST
Created attachment 683841 [details]
File: maps
Comment 8 igor.redhat@gmail.com 2013-01-20 15:30:47 EST
Created attachment 683842 [details]
File: open_fds
Comment 9 igor.redhat@gmail.com 2013-01-20 15:30:49 EST
Created attachment 683843 [details]
File: proc_pid_status
Comment 10 igor.redhat@gmail.com 2013-01-20 15:30:51 EST
Created attachment 683844 [details]
File: var_log_messages
Comment 11 igor.redhat@gmail.com 2013-01-20 15:34:52 EST
Created attachment 683845 [details]
pdf file with the font "Elli" that causes this coredump

Run "fontforge tales.pdf"; when "Pick font" dialog appears, choose font called "Elli". fontforge will crash at that point.
Comment 12 igor.redhat@gmail.com 2013-01-20 15:36:28 EST
This is pretty much the same as bug 789187 that was reported against Fedora 16.
Comment 13 Paul Flo Williams 2013-01-21 10:18:44 EST
This happens on f17 too, but it doesn't happen with the latest upstream head. Unfortunately, it may take some time to identify an appropriate patch.
Comment 14 Paul Flo Williams 2013-02-07 16:25:51 EST
Examining the code that parses PDFs has revealed several array bounds faults that your test case triggers. I'm submitting builds for F18 and F17 at the moment.
Comment 15 Fedora Update System 2013-02-07 16:43:49 EST
fontforge-20120731b-4.fc18 has been submitted as an update for Fedora 18.
https://admin.fedoraproject.org/updates/fontforge-20120731b-4.fc18
Comment 16 Fedora Update System 2013-02-08 00:44:41 EST
fontforge-20120731b-4.fc17 has been submitted as an update for Fedora 17.
https://admin.fedoraproject.org/updates/fontforge-20120731b-4.fc17
Comment 17 Fedora Update System 2013-02-08 11:54:21 EST
Package fontforge-20120731b-4.fc18:
* should fix your issue,
* was pushed to the Fedora 18 testing repository,
* should be available at your local mirror within two days.
Update it with:
# su -c 'yum update --enablerepo=updates-testing fontforge-20120731b-4.fc18'
as soon as you are able to.
Please go to the following url:
https://admin.fedoraproject.org/updates/FEDORA-2013-2117/fontforge-20120731b-4.fc18
then log in and leave karma (feedback).
Comment 18 Fedora Update System 2013-02-18 20:29:37 EST
fontforge-20120731b-4.fc18 has been pushed to the Fedora 18 stable repository.  If problems still persist, please make note of it in this bug report.
Comment 19 Fedora Update System 2013-02-18 20:35:02 EST
fontforge-20120731b-4.fc17 has been pushed to the Fedora 17 stable repository.  If problems still persist, please make note of it in this bug report.