Package: ploticus
Version: 2.42-1
Usertags: goto-cc

During an analysis of all packages using our research compiler tool-chain (using
tools from the cbmc package) the following error was found:

Function PLGG_setup necessarily takes 7 arguments:

http://sources.debian.net/src/ploticus/2.42-1/src/grgd.c?hl=178#L178

Yet the call in PLG_setsize only passes 6 arguments:

http://sources.debian.net/src/ploticus/2.42-1/src/init.c?hl=163#L163

(The call in PLG_init, line 99, does pass all 7 arguments.)

This will cause a stack underflow, resulting in undefined behaviour.

Best,
Michael

Attachment: pgpMX8PSAkfRB.pgp
Description: PGP signature

Reply via email to