Bugzilla – Attachment 60880 Details for
Bug 48778
FILEOPEN arbitrary.pptx will CRASH
Home
|
New
|
Browse
|
Search
|
[?]
|
Reports
|
Help
|
New Account
|
Log In
[x]
|
Forgot Password
Login:
[x]
stacktrace from blank.pptx, second round
fdo48778-stacktrace-from-blank-pptx-2.txt (text/plain), 10.15 KB, created by
Korrawit Pruegsanusak
on 2012-05-02 00:54:42 UTC
(
hide
)
Description:
stacktrace from blank.pptx, second round
Filename:
MIME Type:
Creator:
Korrawit Pruegsanusak
Created:
2012-05-02 00:54:42 UTC
Size:
10.15 KB
patch
obsolete
>******************************************************************************* >* * >* Exception Analysis * >* * >******************************************************************************* > >GetPageUrlData failed, server returned HTTP status 404 >URL requested: http://watson.microsoft.com/StageOne/soffice_bin/3_6_0_0/ooxlo_dll/3_6_0_0/0004fa49.htm?Retriage=1 > >FAULTING_IP: >ooxlo!oox::drawingml::FillProperties::FillProperties+29 >4725fa49 8b08 mov ecx,dword ptr [eax] > >EXCEPTION_RECORD: ffffffff -- (.exr 0xffffffffffffffff) >ExceptionAddress: 4725fa49 (ooxlo!oox::drawingml::FillProperties::FillProperties+0x00000029) > ExceptionCode: c0000005 (Access violation) > ExceptionFlags: 00000000 >NumberParameters: 2 > Parameter[0]: 00000000 > Parameter[1]: 00000000 >Attempt to read from address 00000000 > >FAULTING_THREAD: 00000cac > >DEFAULT_BUCKET_ID: NULL_POINTER_READ > >PROCESS_NAME: soffice.bin > >ERROR_CODE: (NTSTATUS) 0xc0000005 - The instruction at "0x%08lx" referenced memory at "0x%08lx". The memory could not be "%s". > >EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - The instruction at "0x%08lx" referenced memory at "0x%08lx". The memory could not be "%s". > >EXCEPTION_PARAMETER1: 00000000 > >EXCEPTION_PARAMETER2: 00000000 > >READ_ADDRESS: 00000000 > >FOLLOWUP_IP: >ooxlo!oox::drawingml::FillProperties::FillProperties+29 >4725fa49 8b08 mov ecx,dword ptr [eax] > >MOD_LIST: <ANALYSIS/> > >NTGLOBALFLAG: 0 > >APPLICATION_VERIFIER_FLAGS: 0 > >LAST_CONTROL_TRANSFER: from 47542870 to 4725fa49 > >PRIMARY_PROBLEM_CLASS: NULL_POINTER_READ > >BUGCHECK_STR: APPLICATION_FAULT_NULL_POINTER_READ > >STACK_TEXT: >00e3d614 47542870 00000000 98964544 00000009 ooxlo!oox::drawingml::FillProperties::FillProperties+0x29 >00e3d80c 47215fec 00e3d840 0020033f 00e3d83c ooxlo!oox::ppt::SlideFragmentHandler::onCreateContext+0xb20 [d:\libo\oox\source\ppt\slidefragmenthandler.cxx @ 144] >00e3d850 47240ca3 00e3d93c 0020033f 00e3d910 ooxlo!oox::core::ContextHandler2Helper::implCreateChildContext+0x6c [d:\libo\oox\source\core\contexthandler2.cxx @ 109] >00e3d888 64248d8a 05c4f5c0 00e3d93c 0020033f ooxlo!oox::core::FragmentHandler2::createFastChildContext+0xe3 [d:\libo\oox\source\core\fragmenthandler2.cxx @ 121] >00e3d934 64248f3c 048098d0 00000000 00e3d9ac fastsax_uno!sax_fastparser::FastSaxParser::callbackStartElement+0x5de >00e3d944 6424e371 05c0ca50 048098d0 0480e8c0 fastsax_uno!std::deque<sax_fastparser::Entity,std::allocator<sax_fastparser::Entity> >::_Tidy+0x57 >00e3d9ac 6424e96f 0483a1e8 00000000 6425e6c8 fastsax_uno!XML_Parse+0x2328 >00e3d9d8 6424fec3 0483a1e8 0b704809 0b7076f1 fastsax_uno!XML_Parse+0x2926 >00e3da10 64250042 0483a1e8 6425e6c8 0b704809 fastsax_uno!XML_Parse+0x3e7a >00e3da50 642501c4 0483a1e8 0b704807 0b7076f1 fastsax_uno!XML_Parse+0x3ff9 >00e3da6c 6424b30a 0483a1e8 0b7047d0 0b7076f1 fastsax_uno!XML_Parse+0x417b >00e3da94 6424c138 0483a1e8 00002f21 00000000 fastsax_uno!XML_ParseBuffer+0x58 >00e3dac0 6424756e 0483a1e8 05d0f010 00002f21 fastsax_uno!XML_Parse+0xef >00e3db80 64249d55 9894fc8d 4773f218 00e3df0c fastsax_uno!sax_fastparser::FastSaxParser::parse+0x55 >00e3dc74 47220b20 05c0ca64 00e3dcc4 989641e4 fastsax_uno!sax_fastparser::FastSaxParser::parseStream+0x208 >00e3dcac 47220bb4 00e3dcc4 00000000 989641a8 ooxlo!oox::core::FastParser::parseStream+0x90 [d:\libo\oox\source\core\fastparser.cxx @ 121] >00e3dce0 4724d2ee 00e3dd58 00e3ddd4 00000000 ooxlo!oox::core::FastParser::parseStream+0x64 [d:\libo\oox\source\core\fastparser.cxx @ 130] >00e3ddec 4753de3c 00e3e270 98964250 05c0ca50 ooxlo!oox::core::XmlFilterBase::importFragment+0x3ce [d:\libo\oox\source\core\xmlfilterbase.cxx @ 317] >00e3df18 4753c5f2 00e3e270 047c7700 0484dea0 ooxlo!oox::ppt::PresentationFragmentHandler::importSlide+0x75c [d:\libo\oox\source\ppt\presentationfragmenthandler.cxx @ 390] >00e3e2e4 47240954 00e3e3e4 64249d65 05c4c204 ooxlo!oox::ppt::PresentationFragmentHandler::finalizeImport+0xe92 [d:\libo\oox\source\ppt\presentationfragmenthandler.cxx @ 248] >00e3e2ec 64249d65 05c4c204 9894c31d 466093f4 ooxlo!oox::core::FragmentHandler2::endDocument+0x14 [d:\libo\oox\source\core\fragmenthandler2.cxx @ 67] >00e3e3e4 47220b20 05c0ca64 00e3e434 98967954 fastsax_uno!sax_fastparser::FastSaxParser::parseStream+0x218 >00e3e41c 47220bb4 00e3e434 00000000 98967918 ooxlo!oox::core::FastParser::parseStream+0x90 [d:\libo\oox\source\core\fastparser.cxx @ 121] >00e3e450 4724d2ee 00e3e4c8 00e3e544 00000000 ooxlo!oox::core::FastParser::parseStream+0x64 [d:\libo\oox\source\core\fastparser.cxx @ 130] >00e3e55c 4753009f 00e3e5b8 98967880 00e3e594 ooxlo!oox::core::XmlFilterBase::importFragment+0x3ce [d:\libo\oox\source\core\xmlfilterbase.cxx @ 317] >00e3e5c8 4722992d 98967b6c 05cdda94 00e3e5e4 ooxlo!oox::ppt::PowerPointImport::importDocument+0x1cf [d:\libo\oox\source\ppt\pptimport.cxx @ 93] >00e3e624 47530722 0524f900 00e3e7a8 98967b30 ooxlo!oox::core::FilterBase::filter+0x1cd [d:\libo\oox\source\core\filterbase.cxx @ 500] >00e3e678 4643fad9 0524f900 00e3e7a8 f90fbf20 ooxlo!oox::ppt::PowerPointImport::filter+0x32 [d:\libo\oox\source\ppt\pptimport.cxx @ 149] >00e3e7fc 4691ae0a 04752170 00000000 988a64ca sfxlo!SfxObjectShell::ImportFrom+0x929 [d:\libo\sfx2\source\doc\objstor.cxx @ 2238] >00e3e844 46439553 04752170 00000000 f90fb3fc sdlo!sd::DrawDocShell::ImportFrom+0x3a [d:\libo\sd\source\ui\docshell\docshel4.cxx @ 410] >00e3eb20 4647dca0 04752170 f90fb470 4826cc63 sfxlo!SfxObjectShell::DoLoad+0xcb3 [d:\libo\sfx2\source\doc\objstor.cxx @ 730] >00e3ecac 464bd0ad 051d6568 00e3ee2c f90fb7dc sfxlo!SfxBaseModel::load+0x2a0 [d:\libo\sfx2\source\doc\sfxbasemodel.cxx @ 1900] >00e3ef00 5529e4bd 051c8020 00e3ef68 00e3ef70 sfxlo!SfxFrameLoader_Impl::load+0x6ed [d:\libo\sfx2\source\view\frmload.cxx @ 611] >00e3ef84 5529e5f6 fa198446 04cb4d28 04cb4d30 fwklo!framework::LoadEnv::impl_loadContent+0x562 >00e3efc8 55260bc7 fa199ba2 60117abc 04cb4cf8 fwklo!framework::LoadEnv::startLoading+0x93 >00e3f02c 55260d9f 00e3f054 00e3f0e4 00e3f124 fwklo!framework::LoadDispatcher::impl_dispatch+0x170 >00e3f070 5524e59f 04cb4cf8 00e3f0e4 00e3f124 fwklo!framework::LoadDispatcher::dispatch+0x2d >00e3f13c 5524e6de 05cdda9c fa199a26 072e3760 fwklo!framework::DropTargetListener::implts_OpenFile+0x23c >00e3f1a8 4e61028d 072e3760 82e3f1c8 00e3ef46 fwklo!framework::DropTargetListener::drop+0x88 >00e3f224 4e60ee4a 00e3f330 072e3760 00000089 vcllo!DNDListenerContainer::fireDropEvent+0x110 >00e3f284 4e60f31b 05d3fa78 00e3f330 00000082 vcllo!DNDEventDispatcher::fireDropEvent+0xb7 >00e3f2cc 48134e29 046ab700 00e3f330 fae0d12d vcllo!DNDEventDispatcher::drop+0xbd >00e3f30c 48135553 00e3f328 fae0d17d 7c809737 dnd!DropTarget::fire_drop+0x5a >00e3f35c 48131914 05d4e1a4 0008aea8 00000000 dnd!DropTarget::Drop+0x10e >00e3f37c 775f807e 046a8c20 0008aea8 00000000 dnd!IDropTargetImpl::Drop+0x1e >00e3f3b0 77e79dc9 000795f8 00000000 0008b008 ole32!CInterfaceFromWindowProp::PrivDragDrop+0xcd >00e3f3f0 77ef321a 775f7fb1 00e3f404 0000000b RPCRT4!Invoke+0x30 >00e3f818 77ef3bf3 0008a890 00063154 00066364 RPCRT4!NdrStubCall2+0x297 >00e3f870 775fff32 0008a890 00066364 00063154 RPCRT4!CStdStubBuffer_Invoke+0xc6 >00e3f8b0 775ffedc 00066364 0007a3d8 000a0b94 ole32!SyncStubInvoke+0x33 >00e3f8f8 77533237 00066364 0008ab18 0008a890 ole32!StubInvoke+0xa7 >00e3f9d0 7753315c 00063154 00000000 0008a890 ole32!CCtxComChnl::ContextInvoke+0xe3 >00e3f9ec 77533cd5 00066364 00000001 0008a890 ole32!MTAInvoke+0x1a >00e3fa18 7760013c 00066364 00000001 0008a890 ole32!STAInvoke+0x4a >00e3fa4c 775ffcbd 00066310 00063154 0008a890 ole32!AppInvoke+0x7e >00e3fb20 776000f3 00066310 0009eb90 00000400 ole32!ComInvokeWithLockAndIPID+0x2e0 >00e3fb4c 77533d0f 00066310 00000400 0005c830 ole32!ComInvoke+0x60 >00e3fb60 77533b45 00066310 00e3fbe0 77533ab2 ole32!ThreadDispatch+0x23 >00e3fb78 77d48709 007a04e8 0005c430 0000babe ole32!ThreadWndProc+0xfe >00e3fba4 77d487eb 77533ab2 007a04e8 00000400 USER32!InternalCallWinProc+0x28 >00e3fc0c 77d489a5 00000000 77533ab2 007a04e8 USER32!UserCallWinProcCheckWow+0x150 >00e3fc6c 77d489e8 00e3fcb0 00000000 00e3fc88 USER32!DispatchMessageWorker+0x306 >00e3fc7c 4e66d464 00e3fcb0 00e3fc98 4e670d8f USER32!DispatchMessageW+0xf >00e3fc88 4e670d8f 00e3fcb0 77d48bce 00e3fcd0 vcllo!ImplDispatchMessage+0xc >00e3fc98 4e670df9 00e3fcb0 00000001 01686e08 vcllo!WinSalInstance::AcquireYieldMutex+0x36 >00e3fcd0 4e670ee4 00e3fc01 00000000 4e7eb1e0 vcllo!ImplSalYield+0x55 >00e3fcf8 4e492d2c 00e3fc01 00000000 4e7eb148 vcllo!WinSalInstance::Yield+0x99 >00e3fd10 4e492d92 00000001 00000000 00e3fe64 vcllo!ImplYield+0x4c >00e3fd20 4e494201 00000000 00000001 04646e10 vcllo!Application::Yield+0xd >00e3fd30 45fd09e3 f90fa431 4e7eb1de 4e7eb148 vcllo!Application::Execute+0x1e >00e3fe64 4e49a502 00e3e3fa 00403374 0005237f sofficeapp!desktop::Desktop::Main+0xe21 >00e3fe98 4e49a597 016b60f8 00e3ff04 45fe2a56 vcllo!ImplSVMain+0x40 >00e3fea4 45fe2a56 f90fa551 00403374 0005237f vcllo!SVMain+0x1c >00e3ff04 00401079 00e3ff18 0040101a 01685f10 sofficeapp!soffice_main+0x83 >00e3ff0c 0040101a 01685f10 00e3ff30 00401058 soffice!WinMain+0x49 >00e3ff18 00401058 00000002 01685f10 01685f10 soffice!main+0x1a >00e3ff30 00401220 00400000 00000000 0005237f soffice!WinMain+0x28 >00e3ffc0 7c816d4f 00000000 00000000 7ffd9000 soffice!__tmainCRTStartup+0x140 [f:\dd\vctools\crt_bld\self_x86\crt\src\crtexe.c @ 574] >00e3fff0 00000000 004013ff 00000000 00905a4d kernel32!BaseProcessStart+0x23 > > >STACK_COMMAND: .cxr 00000000 ; kb ; dt ntdll!LdrpLastDllInitializer BaseDllName ; dt ntdll!LdrpFailureData ; ~0s ; kb > >SYMBOL_STACK_INDEX: 0 > >SYMBOL_NAME: ooxlo!oox::drawingml::FillProperties::FillProperties+29 > >FOLLOWUP_NAME: MachineOwner > >MODULE_NAME: ooxlo > >IMAGE_NAME: ooxlo.dll > >DEBUG_FLR_IMAGE_TIMESTAMP: 4fa0d08b > >FAILURE_BUCKET_ID: NULL_POINTER_READ_c0000005_ooxlo.dll!oox::drawingml::FillProperties::FillProperties > >BUCKET_ID: APPLICATION_FAULT_NULL_POINTER_READ_ooxlo!oox::drawingml::FillProperties::FillProperties+29 > >WATSON_STAGEONE_URL: http://watson.microsoft.com/StageOne/soffice_bin/3_6_0_0/4fa0bdae/ooxlo_dll/3_6_0_0/4fa0d08b/c0000005/0004fa49.htm?Retriage=1 > >Followup: MachineOwner >---------
You cannot view the attachment while viewing its details because your browser does not support IFRAMEs.
View the attachment on a separate page
.
View Attachment As Raw
Actions:
View
Attachments on
bug 48778
:
60152
|
60153
|
60660
| 60880 |
60947
|
60977