Dominique Pellé wrote:

> valgrind detects a use of uninitialized memory when doing
> the following weird command. It happens in Vim-7.4.909 and
> earlier. This a simplified case which was detected by afl-fuzz
> (http://lcamtuf.coredump.cx/afl/):
> 
> $ echo q | valgrind --track-origins=yes ./vim -u NONE -e -s -c 'debug ls'
> 
> ==2873== Memcheck, a memory error detector
> ==2873== Copyright (C) 2002-2013, and GNU GPL'd, by Julian Seward et al.
> ==2873== Using Valgrind-3.10.0.SVN and LibVEX; rerun with -h for copyright 
> info
> ==2873== Command: ./vim -u NONE -e -s -c debug\ ls
> ==2873==
> ==2873== Conditional jump or move depends on uninitialised value(s)
> ==2873==    at 0x4CB665: msg_puts_printf (message.c:2488)
> ==2873==    by 0x4CA7EE: msg_puts_attr_len (message.c:1941)
> ==2873==    by 0x4C9BFB: msg_outtrans_len_attr (message.c:1455)
> ==2873==    by 0x4C9908: msg_outtrans_len (message.c:1344)
> ==2873==    by 0x484EBB: draw_cmdline (ex_getln.c:2781)
> ==2873==    by 0x48542D: put_on_cmdline (ex_getln.c:2949)
> ==2873==    by 0x483936: getcmdline (ex_getln.c:1734)
> ==2873==    by 0x483F73: getcmdline_prompt (ex_getln.c:2010)
> ==2873==    by 0x463122: do_debug (ex_cmds2.c:169)
> ==2873==    by 0x4635FC: dbg_check_breakpoint (ex_cmds2.c:357)
> ==2873==    by 0x46C448: do_one_cmd (ex_docmd.c:2097)
> ==2873==    by 0x46AA03: do_cmdline (ex_docmd.c:1133)
> ==2873==  Uninitialised value was created by a heap allocation
> ==2873==    at 0x4C2AB80: malloc (in
> /usr/lib/valgrind/vgpreload_memcheck-amd64-linux.so)
> ==2873==    by 0x4E2351: lalloc (misc2.c:921)
> ==2873==    by 0x4E225F: alloc (misc2.c:820)
> ==2873==    by 0x484C47: draw_cmdline (ex_getln.c:2714)
> ==2873==    by 0x48542D: put_on_cmdline (ex_getln.c:2949)
> ==2873==    by 0x483936: getcmdline (ex_getln.c:1734)
> ==2873==    by 0x483F73: getcmdline_prompt (ex_getln.c:2010)
> ==2873==    by 0x463122: do_debug (ex_cmds2.c:169)
> ==2873==    by 0x4635FC: dbg_check_breakpoint (ex_cmds2.c:357)
> ==2873==    by 0x46C448: do_one_cmd (ex_docmd.c:2097)
> ==2873==    by 0x46AA03: do_cmdline (ex_docmd.c:1133)
> ==2873==    by 0x46A03F: do_cmdline_cmd (ex_docmd.c:738)

[...]

Thanks for reporting this.

-- 
How many light bulbs does it take to change a person?

 /// Bram Moolenaar -- [email protected] -- http://www.Moolenaar.net   \\\
///        sponsor Vim, vote for features -- http://www.Vim.org/sponsor/ \\\
\\\  an exciting new programming language -- http://www.Zimbu.org        ///
 \\\            help me help AIDS victims -- http://ICCF-Holland.org    ///

-- 
-- 
You received this message from the "vim_dev" maillist.
Do not top-post! Type your reply below the text you are replying to.
For more information, visit http://www.vim.org/maillist.php

--- 
You received this message because you are subscribed to the Google Groups 
"vim_dev" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
For more options, visit https://groups.google.com/d/optout.

Raspunde prin e-mail lui