#18932 [NEW]: fgetcsv with large line causes Apache segfault
| From: | speedfreak50 at netscape dot net | Date: | Fri, 16 Aug 2002 00:37:03 +0000 |
| Subject: | #18932 [NEW]: fgetcsv with large line causes Apache segfault | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-16966@lists.php.net to get a copy of this message | ||
From: speedfreak50@netscape.net
Operating system: Linux (Red Hat 7.3)
PHP version: 4CVS-2002-08-15
PHP Bug Type: Reproducible crash
Bug description: fgetcsv with large line causes Apache segfault
Below is a .csv file and a script to generate the segfault.
Just tested with php4-STABLE-200208151200 using same ./configure as in
Redhat php-4.1.2 source rpm.
Save this file as /tmp/segfault.csv
------------------------------------
"Xxxxxxxxx Directors Meeting","6/13/2002","4:30:00
PM","6/13/2002","5:30:00
PM","False","False","6/13/2002","4:15:00
PM",,,,,,,,"",,"Normal","False","Normal","2"
"IPM Network Design Review","6/14/2002","1:30:00
PM","6/14/2002","4:00:00
PM","False","False","6/14/2002","1:15:00
PM","xxxxxxxxxxx","xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx;xxxxxxxxxxxxxxxxxxxxxxxxxxxx;xxxxxxxxxxxxxxxxxxxxxxxxxxxxxx",,,,,"
Xxxx - can you bring your projector?
Agenda:
Review IPM network design
Design Document draft to be distributed by EOB 6/6/02 (Thursday)
Decode the XXX sizing spreadsheet
Start construction of consolidated flow map
Build strategy to validate all network assumptions
Notes - need to add ip route-cache flow to XXX downlink interface between
XXXX/04 and XXXX/02 on the 6509
Enumerate netflow generation flows through the 6509 XXXX to provide
netflow architectire diagram.
Rip out exclusion rules for XXX
What is the specification of the field difference between XXX V5 and V7 -
how do we map a XXX to port and install it into XXX?
What are the commission impacts for each modem technology
Why is the xxxxxxxxxxxxx network layer 2 attached to xxxxxxxxxx - is this
a
legacy aspect that needs to be deinstalled - xxxxxxxxxxxxx.
Section 5.2.1 - Change VLAN XXX to VLAN XXX
Future health check consideration would be use use a tcp porbe based upon
collector script that opens and closes based upon service availability
Design XXX for XXX access server off xxxxxxxxxx
Outbound to XXX flows - XXX section - requires engagement with XXX to
define and then design into XXX frontier
Add XXX Access/Access server to XXXxxx
","8/333 Rm F",,"Normal","False","Normal","2"
----------------------------------------
And run this script:
--------------------------------
<?
echo "<html><head></head><body>";
$fp = fopen("/tmp/segfault.csv", 'r');
if (!$fp) {
echo "FALSE<br>";
exit;
}
echo "GETTING CSV<br>";
flush();
while ($line = fgetcsv($fp, 1024, ",")) {
echo "GOT: " . $line[0] . "<br>";
flush();
}
echo "</body></html>";
?>
---------------------------------
Apache child process will crash.
Could this be a remote exploit?
--
Edit bug report at http://bugs.php.net/?id=18932&edit=1
--
Try a CVS snapshot: http://bugs.php.net/fix.php?id=18932&r=trysnapshot
Fixed in CVS: http://bugs.php.net/fix.php?id=18932&r=fixedcvs
Fixed in release: http://bugs.php.net/fix.php?id=18932&r=alreadyfixed
Need backtrace: http://bugs.php.net/fix.php?id=18932&r=needtrace
Try newer version: http://bugs.php.net/fix.php?id=18932&r=oldversion
Not developer issue: http://bugs.php.net/fix.php?id=18932&r=support
Expected behavior: http://bugs.php.net/fix.php?id=18932&r=notwrong
Not enough info: http://bugs.php.net/fix.php?id=18932&r=notenoughinfo
Submitted twice: http://bugs.php.net/fix.php?id=18932&r=submittedtwice
register_globals: http://bugs.php.net/fix.php?id=18932&r=globals