Package: libgctp
Version: 1.0-1
Usertags: goto-cc

During an analysis of all packages using our research compiler tool-chain (using
tools from the cbmc package) the following error was found:

The function gctp requires 19 arguments:

http://sources.debian.net/src/libgctp/1.0-1/gctp.c?hl=70#L70

But only 18 are being passed here:

http://sources.debian.net/src/libgctp/1.0-1/br_gctp.c?hl=26,27

It seems the outdatum parameter (and then argument) is missing here.
Consequently the last few parameters will take possibly unsuitable values and
stack underflow will occur, resulting in undefined behaviour.

Best,
Michael

Attachment: pgp4fDdqn16Ka.pgp
Description: PGP signature

Reply via email to