abrt version: 1.1.18 architecture: i686 Attached file: backtrace, 10329 bytes cmdline: /usr/bin/cdda-player /media/SailorBoysDoItBareback/SailorBoysDoItBareback_scene1_Vidz.com_full.wmv component: libcdio Attached file: coredump, 450560 bytes crash_function: _IO_str_chk_overflow executable: /usr/bin/cdda-player kernel: 2.6.35.12-90.fc14.i686 package: libcdio-0.82-2.fc13 rating: 4 reason: Process /usr/bin/cdda-player was killed by signal 6 (SIGABRT) release: Fedora release 14 (Laughlin) time: 1305690431 uid: 500 How to reproduce ----- 1.I don't know 2. 3.
Created attachment 499515 [details] File: backtrace
Created attachment 499770 [details] proposed patch How to reproduce: 1. create a dir with very long name (more than 80 characters), e.g. /media/someverylong.........dirname 2. cdda-player /media/someverylong.........dirname
There are a couple of insecure use of sprintf on other places, the patch fixes them too.
libcdio-0.82-4.fc15 has been submitted as an update for Fedora 15. https://admin.fedoraproject.org/updates/libcdio-0.82-4.fc15
libcdio-0.82-4.fc14 has been submitted as an update for Fedora 14. https://admin.fedoraproject.org/updates/libcdio-0.82-4.fc14
libcdio-0.82-4.fc13 has been submitted as an update for Fedora 13. https://admin.fedoraproject.org/updates/libcdio-0.82-4.fc13
libcdio-0.78.2-6.el5 has been submitted as an update for Fedora EPEL 5. https://admin.fedoraproject.org/updates/libcdio-0.78.2-6.el5
Package libcdio-0.78.2-6.el5: * should fix your issue, * was pushed to the Fedora EPEL 5 testing repository, * should be available at your local mirror within two days. Update it with: # su -c 'yum update --enablerepo=epel-testing libcdio-0.78.2-6.el5' as soon as you are able to. Please go to the following url: https://admin.fedoraproject.org/updates/libcdio-0.78.2-6.el5 then log in and leave karma (feedback).
libcdio-0.82-4.fc15 has been pushed to the Fedora 15 stable repository. If problems still persist, please make note of it in this bug report.
libcdio-0.82-4.fc14 has been pushed to the Fedora 14 stable repository. If problems still persist, please make note of it in this bug report.
libcdio-0.78.2-6.el5 has been pushed to the Fedora EPEL 5 stable repository. If problems still persist, please make note of it in this bug report.