Skip to content

Segmentation fault in Parser::getObj Function #54

Description

@hkskcy

We’ve fuzzed pdf2json with AFL and found some crashes on Parser::getObj Function.
The input is
crash0.pdf

We found that there are lots of replications in the backtrace, forming as Parser::getObj -> Parser::makeStream -> Object::dictLookup -> XRef::fetch.
This indicates that pdf2json encountered an infinite recursive call in the getObj function, which ultimately led to a stack overflow.
The outputs of gdb, gdb backtrace and valgrind are show below.

gdb says: There is no error in the output.
gdb

gdb backtrace shows:
gdb_bt

valgrind shows:
valgrind

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions