Hide Forgot
Created attachment 500243 [details] Minimized input file Description of problem: Cups crashing with segfault on attached config file. Version-Release number of selected component (if applicable): Version : 1.4.2 Release : 35.el6_0.1 How reproducible: Always Steps to Reproduce: 1. download attachment 2. run /usr/sbin/cupsd -f -c ./min Actual results: Segmentation fault Expected results: Proper error handling Additional info: Fault discovered by fuzzing the configuration file.
Created attachment 500244 [details] GDB short trace
Created attachment 500245 [details] GDB full trace
Created attachment 500246 [details] Valgrind output
Created attachment 500250 [details] GDB short trace #2 Similar error in parse_aaa function (parsing logic). I will provide additional information if required.
Patch: http://www.cups.org/strfiles/3861/str3861.patch
Since the problem described in this bug report should be resolved in a recent advisory, it has been closed with a resolution of ERRATA. For information on the advisory, and where to find the updated files, follow the link below. If the solution does not work for you, open a new bug report. http://rhn.redhat.com/errata/RHSA-2011-1635.html