New issue
Advanced search Search tips
Starred by 1 user
Status: Fixed
Owner:
Closed: Jun 2016
Cc:



Sign in to add a comment
Wireshark SIGSEGV in erf_meta_read_tag
Project Member Reported by mjurczyk@google.com, Apr 19 2016 Back to list
The following SIGSEGV crash due to an invalid memory read can be observed in an ASAN build of Wireshark (current git master), by feeding a malformed file to tshark ("$ ./tshark -nVxr /path/to/file"):

--- cut ---
==28415==ERROR: AddressSanitizer: SEGV on unknown address 0x61b000022d84 (pc 0x7f0e1b0002a2 bp 0x7ffde25a76f0 sp 0x7ffde25a7630 T0)
    #0 0x7f0e1b0002a1 in erf_meta_read_tag wireshark/wiretap/erf.c:1242:13
    #1 0x7f0e1afff0f0 in populate_summary_info wireshark/wiretap/erf.c:1851:27
    #2 0x7f0e1aff34d6 in erf_read wireshark/wiretap/erf.c:447:7
    #3 0x7f0e1b1a746b in wtap_read wireshark/wiretap/wtap.c:1245:7
    #4 0x528196 in load_cap_file wireshark/tshark.c:3478:12
    #5 0x51e67c in main wireshark/tshark.c:2192:13

AddressSanitizer can not provide additional info.
SUMMARY: AddressSanitizer: SEGV wireshark/wiretap/erf.c:1242:13 in erf_meta_read_tag
==28415==ABORTING
--- cut ---

The crash was reported at https://bugs.wireshark.org/bugzilla/show_bug.cgi?id=12352. Attached are three files which trigger the crash.

This bug is subject to a 90 day disclosure deadline. If 90 days elapse without a broadly available patch, then the bug report will automatically become visible to the public.
 
signal_sigsegv_7ffff7b67fa2_930_712b38a71209506d41ae107e2dca78b1582f401beba23f00.pcap
26 bytes Download
signal_sigsegv_7ffff7b67fa2_931_d6b661a05a68cf9074717b110873b5b59341ed3f8f0e871f.pcap
26 bytes Download
signal_sigsegv_7ffff7b67fa2_6274_03cfc355724d27bfdf42ff3ee785d8e9faef56a1fd044f99.cap
42 bytes Download
Project Member Comment 1 by mjurczyk@google.com, Apr 28 2016
Cc: mjurczyk@google.com
Issue 805 has been merged into this issue.
Project Member Comment 2 by mjurczyk@google.com, Jun 1 2016
Labels: -Restrict-View-Commit Fixed-2016-May-22
Status: Fixed
Fixed in https://code.wireshark.org/review/#/c/15357/.
Sign in to add a comment