Bug #52929 [Opn]: Segfault in filter_var with FILTER_VALIDATE_EMAIL with large amount of data

From: Date: Mon, 27 Sep 2010 05:24:16 +0000
Subject: Bug #52929 [Opn]: Segfault in filter_var with FILTER_VALIDATE_EMAIL with large amount of data
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-154657@lists.php.net to get a copy of this message
Edit report at http://bugs.php.net/bug.php?id=52929&edit=1

 ID:                 52929
 Updated by:         rasmus@php.net
 Reported by:        neufeind@php.net
 Summary:            Segfault in filter_var with FILTER_VALIDATE_EMAIL
                     with large amount of data
 Status:             Open
 Type:               Bug
 Package:            Filter related
 PHP Version:        5.3.3
 Block user comment: N

 New Comment:

Perhaps a simple pre-filter before we hit the regex.  You can't actually
have an 
8k email address.  There are length limits both before and after the @.


Previous Comments:
------------------------------------------------------------------------
[2010-09-27 05:21:50] aharvey@php.net

I hate you, Chrome.

Anyway, as I was saying, I'm not terribly comfortable closing this, 
since it's likely sites will actually be passing user data straight to 
filter_var(). I mean, that's what it's there for. Is it worth
revisiting the decision to compile our bundled libpcre in its default
stack recursive mode? I know NO_RECURSE is slower, but I'm nervous
about potential remote crashers.

------------------------------------------------------------------------
[2010-09-27 05:19:58] aharvey@php.net

This is the normal issue with heavily nested regular expressions
exhausting the available stack size. I can upload a backtrace if
there's a sudden desire to see several thousand recursive
invocations of PCRE's match function. :)

I'm not really comfortable closing this, even though we normally just
close 
preg_replace

------------------------------------------------------------------------
[2010-09-27 02:38:06] neufeind@php.net

Looking at the source at
http://svn.php.net/viewvc/php/php-src/trunk/ext/filter/logical_filters.c?view=markup
I wonder if the problem itself might be in the pcre-lib used since the
email-validation itself is PCRE-based? Fedora Linux here ships with PCRE
7.8.

------------------------------------------------------------------------
[2010-09-27 02:09:24] neufeind@php.net

Description:
------------
Using the attached test-script with just a large amount of data (e.g.
8kb of just "x") segfaults php. Tried with 5.3.3 (Fedora) and also some
5.3.4-snapshot that I could get hold of.

Crashed for me with around 8kb of data. If it works fine for you, maybe
increase that limit to 16kb or so.

Test script:
---------------
<?php
  $email = file_get_contents('x.data');
  $r = filter_var($email, FILTER_VALIDATE_EMAIL);
  var_dump($r);

// and just dump a large number of characters like "x" in x.data
// for a in seq 1 8000; do echo -n x>>x.data; done

Expected result:
----------------
bool(false)

Actual result:
--------------
segfault


------------------------------------------------------------------------



-- 
Edit this bug report at http://bugs.php.net/bug.php?id=52929&edit=1


Thread (15 messages)

« previous php.bugs (#154657) next »