[Bug 20896] New: Use-after-free in DdeClientTransaction in user32 dde tests

wine-bugs at winehq.org wine-bugs at winehq.org
Tue Dec 1 20:35:09 CST 2009


           Summary: Use-after-free in DdeClientTransaction in user32 dde
           Product: Wine
           Version: 1.1.33
          Platform: PC
        OS/Version: Linux
            Status: NEW
          Keywords: download, source, testcase
          Severity: normal
          Priority: P2
         Component: user32
        AssignedTo: wine-bugs at winehq.org
        ReportedBy: dank at kegel.com

 Invalid read of size 2
    at  GlobalFree (heap.c:767)
    by  WDML_FreeTransaction (dde_misc.c:2439)
    by  DdeClientTransaction (dde_client.c:1228)
    by  test_ddeml_client (dde.c:392)
    by  func_dde (dde.c:2357)
    by  run_test (test.h:535)
    by  main (test.h:585)
  Address 0x7f075e80 is not stack'd, malloc'd or (recently) free'd
It's a little hard to see what's going on, but it
appears that the memory in question was indeed recently freed,
judging by the attached log, which was generated by the command

WINEDEBUG=+relay,+heap valgrind --trace-children=yes wine user32_test.exe.so

and edited to show just the area of interest.

Configure bugmail: http://bugs.winehq.org/userprefs.cgi?tab=email
Do not reply to this email, post in Bugzilla using the
above URL to reply.
------- You are receiving this mail because: -------
You are watching all bug changes.

More information about the wine-bugs mailing list