Wireshark-bugs: [Wireshark-bugs] [Bug 11075] New: Buildbot crash output: fuzz-2015-03-22-3793.pc

Date: Tue, 24 Mar 2015 05:00:02 +0000
Bug ID 11075
Summary Buildbot crash output: fuzz-2015-03-22-3793.pcap
Product Wireshark
Version unspecified
Hardware x86-64
URL https://www.wireshark.org/download/automated/captures/fuzz-2015-03-22-3793.pcap
OS Ubuntu
Status CONFIRMED
Severity Major
Priority High
Component Dissection engine (libwireshark)
Assignee [email protected]
Reporter [email protected]

Problems have been found with the following capture file:

https://www.wireshark.org/download/automated/captures/fuzz-2015-03-22-3793.pcap

stderr:
Input file: /home/wireshark/menagerie/menagerie/frame_comp.enc

Build host information:
Linux wsbb04 3.13.0-46-generic #79-Ubuntu SMP Tue Mar 10 20:06:50 UTC 2015
x86_64 x86_64 x86_64 GNU/Linux
Distributor ID:    Ubuntu
Description:    Ubuntu 14.04.2 LTS
Release:    14.04
Codename:    trusty

Buildbot information:
BUILDBOT_REPOSITORY=ssh://[email protected]:29418/wireshark
BUILDBOT_BUILDNUMBER=3191
BUILDBOT_URL=http://buildbot.wireshark.org/trunk/
BUILDBOT_BUILDERNAME=Clang Code Analysis
BUILDBOT_SLAVENAME=clang-code-analysis
BUILDBOT_GOT_REVISION=2afb52461cd379c2e13d8f29f6436c50279aa399

Return value:  0

Dissector bug:  0

Valgrind error count:  9



Git commit
commit 2afb52461cd379c2e13d8f29f6436c50279aa399
Author: Alexander Stein <[email protected]>
Date:   Mon Mar 16 20:21:38 2015 +0100

    MQTT: Dissect on default port automatically

    There is a IANA reserved port number for MQTT: 1883

    Change-Id: I9bc3c83b9d7eda291728fe7311f4b7a817d3a833
    Signed-off-by: Alexander Stein <[email protected]>
    Reviewed-on: https://code.wireshark.org/review/7770
    Reviewed-by: Pascal Quantin <[email protected]>
    Reviewed-by: Michael Mann <[email protected]>


Command and args: ./tools/valgrind-wireshark.sh 

==2270== Memcheck, a memory error detector
==2270== Copyright (C) 2002-2013, and GNU GPL'd, by Julian Seward et al.
==2270== Using Valgrind-3.10.0.SVN and LibVEX; rerun with -h for copyright info
==2270== Command:
/home/wireshark/builders/wireshark-master-fuzz/clangcodeanalysis/install/bin/tshark
-nr /fuzz/buildbot/clangcodeanalysis/valgrind-fuzz/fuzz-2015-03-22-3793.pcap
==2270== 
==2270== Conditional jump or move depends on uninitialised value(s)
==2270==    at 0x69E634F: dissect_fr_nlpid (packet-fr.c:668)
==2270==    by 0x69E5B55: dissect_fr_uncompressed (packet-fr.c:650)
==2270==    by 0x670B66D: call_dissector_work (packet.c:614)
==2270==    by 0x670AC1C: call_dissector_with_data (packet.c:2373)
==2270==    by 0x6ECD8A3: dissect_wcp (packet-wcp.c:391)
==2270==    by 0x670B66D: call_dissector_work (packet.c:614)
==2270==    by 0x670B739: dissector_try_uint (packet.c:1132)
==2270==    by 0x69E651A: dissect_fr_nlpid (packet-fr.c:759)
==2270==    by 0x69E6122: dissect_fr_common (packet-fr.c:561)
==2270==    by 0x670B66D: call_dissector_work (packet.c:614)
==2270==    by 0x670B739: dissector_try_uint (packet.c:1132)
==2270==    by 0x69E7CE3: dissect_frame (packet-frame.c:496)
==2270== 
==2270== Use of uninitialised value of size 8
==2270==    at 0x9F05593: g_hash_table_lookup (in
/lib/x86_64-linux-gnu/libglib-2.0.so.0.4002.0)
==2270==    by 0x670B707: dissector_try_uint (packet.c:865)
==2270==    by 0x69E63E2: dissect_fr_nlpid (packet-fr.c:714)
==2270==    by 0x69E5B55: dissect_fr_uncompressed (packet-fr.c:650)
==2270==    by 0x670B66D: call_dissector_work (packet.c:614)
==2270==    by 0x670AC1C: call_dissector_with_data (packet.c:2373)
==2270==    by 0x6ECD8A3: dissect_wcp (packet-wcp.c:391)
==2270==    by 0x670B66D: call_dissector_work (packet.c:614)
==2270==    by 0x670B739: dissector_try_uint (packet.c:1132)
==2270==    by 0x69E651A: dissect_fr_nlpid (packet-fr.c:759)
==2270==    by 0x69E6122: dissect_fr_common (packet-fr.c:561)
==2270==    by 0x670B66D: call_dissector_work (packet.c:614)
==2270== 
==2270== Conditional jump or move depends on uninitialised value(s)
==2270==    at 0x9F055CC: g_hash_table_lookup (in
/lib/x86_64-linux-gnu/libglib-2.0.so.0.4002.0)
==2270==    by 0x670B707: dissector_try_uint (packet.c:865)
==2270==    by 0x69E63E2: dissect_fr_nlpid (packet-fr.c:714)
==2270==    by 0x69E5B55: dissect_fr_uncompressed (packet-fr.c:650)
==2270==    by 0x670B66D: call_dissector_work (packet.c:614)
==2270==    by 0x670AC1C: call_dissector_with_data (packet.c:2373)
==2270==    by 0x6ECD8A3: dissect_wcp (packet-wcp.c:391)
==2270==    by 0x670B66D: call_dissector_work (packet.c:614)
==2270==    by 0x670B739: dissector_try_uint (packet.c:1132)
==2270==    by 0x69E651A: dissect_fr_nlpid (packet-fr.c:759)
==2270==    by 0x69E6122: dissect_fr_common (packet-fr.c:561)
==2270==    by 0x670B66D: call_dissector_work (packet.c:614)
==2270== 
==2270== Use of uninitialised value of size 8
==2270==    at 0x9F055D6: g_hash_table_lookup (in
/lib/x86_64-linux-gnu/libglib-2.0.so.0.4002.0)
==2270==    by 0x670B707: dissector_try_uint (packet.c:865)
==2270==    by 0x69E63E2: dissect_fr_nlpid (packet-fr.c:714)
==2270==    by 0x69E5B55: dissect_fr_uncompressed (packet-fr.c:650)
==2270==    by 0x670B66D: call_dissector_work (packet.c:614)
==2270==    by 0x670AC1C: call_dissector_with_data (packet.c:2373)
==2270==    by 0x6ECD8A3: dissect_wcp (packet-wcp.c:391)
==2270==    by 0x670B66D: call_dissector_work (packet.c:614)
==2270==    by 0x670B739: dissector_try_uint (packet.c:1132)
==2270==    by 0x69E651A: dissect_fr_nlpid (packet-fr.c:759)
==2270==    by 0x69E6122: dissect_fr_common (packet-fr.c:561)
==2270==    by 0x670B66D: call_dissector_work (packet.c:614)
==2270== 
==2270== Conditional jump or move depends on uninitialised value(s)
==2270==    at 0x9F055F2: g_hash_table_lookup (in
/lib/x86_64-linux-gnu/libglib-2.0.so.0.4002.0)
==2270==    by 0x670B707: dissector_try_uint (packet.c:865)
==2270==    by 0x69E63E2: dissect_fr_nlpid (packet-fr.c:714)
==2270==    by 0x69E5B55: dissect_fr_uncompressed (packet-fr.c:650)
==2270==    by 0x670B66D: call_dissector_work (packet.c:614)
==2270==    by 0x670AC1C: call_dissector_with_data (packet.c:2373)
==2270==    by 0x6ECD8A3: dissect_wcp (packet-wcp.c:391)
==2270==    by 0x670B66D: call_dissector_work (packet.c:614)
==2270==    by 0x670B739: dissector_try_uint (packet.c:1132)
==2270==    by 0x69E651A: dissect_fr_nlpid (packet-fr.c:759)
==2270==    by 0x69E6122: dissect_fr_common (packet-fr.c:561)
==2270==    by 0x670B66D: call_dissector_work (packet.c:614)
==2270== 
==2270== Use of uninitialised value of size 8
==2270==    at 0x9F05659: g_hash_table_lookup (in
/lib/x86_64-linux-gnu/libglib-2.0.so.0.4002.0)
==2270==    by 0x670B707: dissector_try_uint (packet.c:865)
==2270==    by 0x69E63E2: dissect_fr_nlpid (packet-fr.c:714)
==2270==    by 0x69E5B55: dissect_fr_uncompressed (packet-fr.c:650)
==2270==    by 0x670B66D: call_dissector_work (packet.c:614)
==2270==    by 0x670AC1C: call_dissector_with_data (packet.c:2373)
==2270==    by 0x6ECD8A3: dissect_wcp (packet-wcp.c:391)
==2270==    by 0x670B66D: call_dissector_work (packet.c:614)
==2270==    by 0x670B739: dissector_try_uint (packet.c:1132)
==2270==    by 0x69E651A: dissect_fr_nlpid (packet-fr.c:759)
==2270==    by 0x69E6122: dissect_fr_common (packet-fr.c:561)
==2270==    by 0x670B66D: call_dissector_work (packet.c:614)
==2270== 
==2270== Use of uninitialised value of size 8
==2270==    at 0x9F05641: g_hash_table_lookup (in
/lib/x86_64-linux-gnu/libglib-2.0.so.0.4002.0)
==2270==    by 0x670B707: dissector_try_uint (packet.c:865)
==2270==    by 0x69E63E2: dissect_fr_nlpid (packet-fr.c:714)
==2270==    by 0x69E5B55: dissect_fr_uncompressed (packet-fr.c:650)
==2270==    by 0x670B66D: call_dissector_work (packet.c:614)
==2270==    by 0x670AC1C: call_dissector_with_data (packet.c:2373)
==2270==    by 0x6ECD8A3: dissect_wcp (packet-wcp.c:391)
==2270==    by 0x670B66D: call_dissector_work (packet.c:614)
==2270==    by 0x670B739: dissector_try_uint (packet.c:1132)
==2270==    by 0x69E651A: dissect_fr_nlpid (packet-fr.c:759)
==2270==    by 0x69E6122: dissect_fr_common (packet-fr.c:561)
==2270==    by 0x670B66D: call_dissector_work (packet.c:614)
==2270== 
==2270== Conditional jump or move depends on uninitialised value(s)
==2270==    at 0x68C7FE8: dissect_clnp (packet-clnp.c:241)
==2270==    by 0x670B66D: call_dissector_work (packet.c:614)
==2270==    by 0x670B739: dissector_try_uint (packet.c:1132)
==2270==    by 0x69E63E2: dissect_fr_nlpid (packet-fr.c:714)
==2270==    by 0x69E5B55: dissect_fr_uncompressed (packet-fr.c:650)
==2270==    by 0x670B66D: call_dissector_work (packet.c:614)
==2270==    by 0x670AC1C: call_dissector_with_data (packet.c:2373)
==2270==    by 0x6ECD8A3: dissect_wcp (packet-wcp.c:391)
==2270==    by 0x670B66D: call_dissector_work (packet.c:614)
==2270==    by 0x670B739: dissector_try_uint (packet.c:1132)
==2270==    by 0x69E651A: dissect_fr_nlpid (packet-fr.c:759)
==2270==    by 0x69E6122: dissect_fr_common (packet-fr.c:561)
==2270== 
==2270== Conditional jump or move depends on uninitialised value(s)
==2270==    at 0x6C9CCD4: dissect_ositp_internal (packet-ositp.c:2136)
==2270==    by 0x670B64F: call_dissector_work (packet.c:612)
==2270==    by 0x670AC1C: call_dissector_with_data (packet.c:2373)
==2270==    by 0x68C8149: dissect_clnp (packet-clnp.c:248)
==2270==    by 0x670B66D: call_dissector_work (packet.c:614)
==2270==    by 0x670B739: dissector_try_uint (packet.c:1132)
==2270==    by 0x69E63E2: dissect_fr_nlpid (packet-fr.c:714)
==2270==    by 0x69E5B55: dissect_fr_uncompressed (packet-fr.c:650)
==2270==    by 0x670B66D: call_dissector_work (packet.c:614)
==2270==    by 0x670AC1C: call_dissector_with_data (packet.c:2373)
==2270==    by 0x6ECD8A3: dissect_wcp (packet-wcp.c:391)
==2270==    by 0x670B66D: call_dissector_work (packet.c:614)
==2270== 
==2270== 
==2270== HEAP SUMMARY:
==2270==     in use at exit: 1,222,303 bytes in 29,855 blocks
==2270==   total heap usage: 231,871 allocs, 202,016 frees, 31,828,505 bytes
allocated
==2270== 
==2270== LEAK SUMMARY:
==2270==    definitely lost: 3,352 bytes in 144 blocks
==2270==    indirectly lost: 37,224 bytes in 51 blocks
==2270==      possibly lost: 0 bytes in 0 blocks
==2270==    still reachable: 1,181,727 bytes in 29,660 blocks
==2270==         suppressed: 0 bytes in 0 blocks
==2270== Rerun with --leak-check=full to see details of leaked memory
==2270== 
==2270== For counts of detected and suppressed errors, rerun with: -v
==2270== Use --track-origins=yes to see where uninitialised values come from
==2270== ERROR SUMMARY: 9 errors from 9 contexts (suppressed: 1 from 1)

[ no debug trace ]


You are receiving this mail because:
  • You are watching all bug changes.