Bug 121349 - Mail causes evo crash.
Mail causes evo crash.
Status: CLOSED RAWHIDE
Product: Fedora
Classification: Fedora
Component: evolution (Show other bugs)
2
All Linux
medium Severity medium
: ---
: ---
Assigned To: Dave Malcolm
: Security
Depends On:
Blocks:
  Show dependency treegraph
 
Reported: 2004-04-20 13:06 EDT by David Woodhouse
Modified: 2007-11-30 17:10 EST (History)
4 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2004-12-20 05:02:02 EST
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)
Mail which crashes Evolution (14.43 KB, application/octet-stream)
2004-04-20 13:12 EDT, David Woodhouse
no flags Details

  None (edit)
Description David Woodhouse 2004-04-20 13:06:48 EDT
Even with the preview window closed, evolution crashes on selecting
the (soon to be) attached email. 

received: * 120 FETCH (UID 946 BODY ("TEXT" "PLAIN" ("charset"
"US-ASCII") NIL NIL "7bit" 13094 128))
received: A00077 OK Fetch completed.
 
(evolution:26157): camel-WARNING **: Truncated utf8 buffer
(evolution:26157): camel-WARNING **: Truncated utf8 buffer
(evolution:26157): camel-WARNING **: Truncated utf8 buffer
(evolution:26157): camel-WARNING **: Truncated utf8 buffer
(evolution:26157): camel-WARNING **: Truncated utf8 buffer
(evolution:26157): gtkhtml-WARNING **: invalid character value: x30229a9d
(evolution:26157): camel-WARNING **: Truncated utf8 buffer
(evolution:26157): camel-WARNING **: Truncated utf8 buffer
(evolution:26157): camel-WARNING **: Truncated utf8 buffer
(evolution:26157): gtkhtml-WARNING **: invalid character value: x3c044ccd
(evolution:26157): camel-WARNING **: Truncated utf8 buffer
(evolution:26157): camel-WARNING **: Truncated utf8 buffer
(evolution:26157): camel-WARNING **: Truncated utf8 buffer
(evolution:26157): camel-WARNING **: Truncated utf8 buffer
(evolution:26157): camel-WARNING **: Truncated utf8 buffer
(evolution:26157): camel-WARNING **: Truncated utf8 buffer
(evolution:26157): camel-WARNING **: Truncated utf8 buffer
(evolution:26157): camel-WARNING **: Truncated utf8 buffer
(evolution:26157): camel-WARNING **: Truncated utf8 buffer
(evolution:26157): camel-WARNING **: Truncated utf8 buffer
(evolution:26157): camel-WARNING **: Truncated utf8 buffer
(evolution:26157): camel-WARNING **: Truncated utf8 buffer
(evolution:26157): camel-WARNING **: Truncated utf8 buffer
(evolution:26157): camel-WARNING **: Truncated utf8 buffer
(evolution:26157): camel-WARNING **: Truncated utf8 buffer
(evolution:26157): camel-WARNING **: Truncated utf8 buffer
(evolution:26157): camel-WARNING **: Truncated utf8 buffer
(evolution:26157): camel-WARNING **: Truncated utf8 buffer
(evolution:26157): gtkhtml-WARNING **: invalid character value: x1e7331d
(evolution:26157): gtkhtml-WARNING **: invalid character value: x1b1740d
(evolution:26157): gtkhtml-WARNING **: invalid character value: x16c006d
camel-ERROR **: file camel-url-scanner.c: line 147
(camel_url_addrspec_start): assertion failed: (*inptr == '@')
aborting...
Comment 1 David Woodhouse 2004-04-20 13:09:57 EDT
#0  0x0fcad170 in __waitpid_nocancel () from /lib/tls/libpthread.so.0
#1  0x0f28a5e0 in libgnomeui_module_info_get () from
/usr/lib/libgnomeui-2.so.0
#2  <signal handler called>
#3  0x0fea067c in raise () from /lib/tls/libc.so.6
#4  0x0fea2150 in abort () from /lib/tls/libc.so.6
#5  0x0f9d46c4 in g_logv () from /usr/lib/libglib-2.0.so.0
#6  0x0f9d4730 in g_log () from /usr/lib/libglib-2.0.so.0
#7  0x0ec2aff0 in camel_url_addrspec_start ()
   from /usr/lib/evolution/1.4/libcamel.so.0
#8  0x0ec2aed8 in camel_url_scanner_scan ()
   from /usr/lib/evolution/1.4/libcamel.so.0
#9  0x0ebf6e68 in camel_mime_filter_tohtml_get_type ()
   from /usr/lib/evolution/1.4/libcamel.so.0
#10 0x0ebf8004 in camel_mime_filter_new ()
   from /usr/lib/evolution/1.4/libcamel.so.0
#11 0x0ec201b4 in camel_stream_filter_remove ()
   from /usr/lib/evolution/1.4/libcamel.so.0
#12 0x0ec223c0 in camel_stream_write ()
   from /usr/lib/evolution/1.4/libcamel.so.0
#13 0x0e2594fc in mail_format_get_data_wrapper_text ()
   from /usr/lib/evolution/1.4/components/libevolution-mail.so
#14 0x0e257d44 in mail_part_toggle_displayed ()
   from /usr/lib/evolution/1.4/components/libevolution-mail.so
#15 0x0e252744 in mail_display_render ()
   from /usr/lib/evolution/1.4/components/libevolution-mail.so
#16 0x0e252ac8 in mail_display_redisplay ()
   from /usr/lib/evolution/1.4/components/libevolution-mail.so
#17 0x0e252bb0 in mail_display_set_message ()
   from /usr/lib/evolution/1.4/components/libevolution-mail.so
#18 0x0e2350c4 in hide_sender ()
   from /usr/lib/evolution/1.4/components/libevolution-mail.so
#19 0x0e26565c in mail_empty_trash ()
   from /usr/lib/evolution/1.4/components/libevolution-mail.so
#20 0x0e25fe00 in mail_msg_wait_all ()
   from /usr/lib/evolution/1.4/components/libevolution-mail.so
#21 0x0f9f4360 in g_vasprintf () from /usr/lib/libglib-2.0.so.0
#22 0x0f9ca978 in g_main_depth () from /usr/lib/libglib-2.0.so.0
#23 0x0f9cbe88 in g_main_context_dispatch () from
/usr/lib/libglib-2.0.so.0
#24 0x0f9cc258 in g_main_context_dispatch () from
/usr/lib/libglib-2.0.so.0
#25 0x0f9cca64 in g_main_loop_run () from /usr/lib/libglib-2.0.so.0
#26 0x0f4960c0 in bonobo_main () from /usr/lib/libbonobo-2.so.0
#27 0x10054700 in main ()
Comment 2 David Woodhouse 2004-04-20 13:12:46 EDT
Created attachment 99567 [details]
Mail which crashes Evolution
Comment 3 Alan Cox 2004-05-02 20:08:58 EDT
Dave can you poke mjc@redhat about this one and get him to push it out
to vendor-sec
Comment 4 Mark J. Cox (Product Security) 2004-05-24 06:41:09 EDT
I wasn't able to reproduce this in a quick test (mail in INBOX in
local file, utf-8 default charset, default FC2 install+FC2 evo)
Comment 5 Phil Schaffner 2004-05-26 23:45:34 EDT
Have seen this bug with several mail messages from Lindows.com and
from my local PBS station.  Workaround is to select "View/Message
Display/Show Email Source" or the crash will occur whenever the
problematic folder is selected.
Comment 6 Phil Schaffner 2004-05-27 00:27:05 EDT
Should have tried again before last comment.  Seems to be fixed in
unstable (maybe metastable? :-) evolution-1.5.8-2 - same messages that
previously caused crashes consistently through several evolution
versions now display without problems.
Comment 7 Mark J. Cox (Product Security) 2004-05-27 03:54:22 EDT
Philip, could you attach or send (forward a copy to my email address)
a sample message so we can track this down?  Thanks.
Comment 8 David Woodhouse 2004-05-27 04:32:18 EDT
Mark, try it from an IMAP server -- particularly from dovecot.
Comment 9 David Woodhouse 2004-05-27 06:30:50 EDT
It doesn't happen in 1.5.8 for me either. It was happening in 1.5.7.
Comment 10 David Woodhouse 2004-05-27 06:44:06 EDT
cf. http://bugzilla.ximian.com/show_bug.cgi?id=59169
Comment 11 Josh Bressers 2004-06-14 15:44:27 EDT
I've tried to reproduce this using evolution on FC2 and RHEL3 with no
luck.

I tried using the mailbox Phillip sent mjc and the message dwmw2 posted.
Both were verified using dovecot and a local mbox file.

I'm stuck at the moment unless someone can produce a message which can
reproduce the issue.
Comment 12 Phil Schaffner 2004-06-15 10:04:14 EDT
You've got messages that trigger the issue.  What is apparently
lacking is a replication of the configuration in which the crashes
occur.  Perhaps this bug should be changed to RESOLVED/RAWHIDE unless
someone can replicate it with current packages?

Note You need to log in before you can comment on or make changes to this bug.