Bug #62523 [Com]: php crashes with segfault when exif_read_data called
| From: | kbinaz at gmail dot com | Date: | Wed, 23 Oct 2013 01:25:48 +0000 |
| Subject: | Bug #62523 [Com]: php crashes with segfault when exif_read_data called | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-182400@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=62523&edit=1
ID: 62523
Comment by: kbinaz at gmail dot com
Reported by: bigbug at mafia dot lv
Summary: php crashes with segfault when exif_read_data called
Status: Feedback
Type: Bug
Package: Reproducible crash
Operating System: linux
PHP Version: 5.3Git-2012-07-10 (snap)
Assigned To: rasmus
Block user comment: N
Private report: N
New Comment:
To expand on my last comment, the patch from Dominic fixed the SegFault, but caused other issues
with reading the majority of the exif data. I was no longer able to read other meta-data including
Orientation, and had to revert.
Here are some of the details from my setup:
CentOS 5.9 x86_64
PHP 5.5.4
- File -
<?
$array = exif_read_data('file.jpg');
print_r($array);
exit;
?>
- Output -
php test.php
PHP Warning: exif_read_data(file.jpg): Incorrect APP1 Exif Identifier Code in
/home/xoticspottest/site/test.php on line 2
Segmentation fault
- Strace php test.php -
...
read(3, "\377\330\377\340\0\20JFIF\0\1\1\1\0H\0H\0\0\377\341\v\273http://n"..., 8192) = 8192
write(2, "PHP Warning: exif_read_data(101"..., 140PHP Warning: exif_read_data(file.jpg):
Incorrect APP1 Exif Identifier Code in /home/xoticspottest/site/test.php on line 2) = 140
read(3, "\0^\17\0\0\230\0\3\0\4\0\0\0^\23\0\0\231\0\4\0J\0\0\0f\23\0\0\232\0\4"..., 8192)
= 8192
read(3, "\1\3\21\1\377\304\0\37\0\0\1\5\1\1\1\1\1\1\0\0\0\0\0\0\0\0\1\2\3\4\5\6"..., 8192)
= 8192
mmap(NULL, 266240, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x2acd7c444000
mmap(NULL, 266240, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x2acd7c485000
close(3) = 0
mmap(NULL, 266240, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x2acd7c4c6000
--- SIGSEGV (Segmentation fault) @ 0 (0) ---
+++ killed by SIGSEGV +++
If needed, email me for the sample jpg. I can't put it on a public URL due to licensing issues.
Previous Comments:
------------------------------------------------------------------------
[2013-10-22 13:22:19] glen at delfi dot ee
please note that this patch makes 64bit platforms crash due misuse of int (4 bytes) vs size_t
(8bytes)
https://code.google.com/p/php52-backports/issues/detail?id=36
attaching fix to that ticket there
------------------------------------------------------------------------
[2013-10-22 05:10:40] pajoye@php.net
Same here, using latest 5.5 or snaps:
php_exif.dll!php_ifd_get16u(void * value, int motorola_intel) Line 1095 C
php_exif.dll!exif_iif_add_value(image_info_type * image_info, int section_index, char * name, int
tag, int format, int length, void * value, int motorola_intel, void * * * tsrm_ls) Line 1754 C
php_exif.dll!exif_process_IFD_TAG(image_info_type * ImageInfo, char * dir_entry, char * offset_base,
unsigned int IFDlength, unsigned int displacement, int section_index, int ReadNextIFD, const
tag_info_type * tag_table, void * * * tsrm_ls) Line 3111 C
php_exif.dll!exif_process_IFD_in_MAKERNOTE(image_info_type * ImageInfo, char * value_ptr, int
value_len, char * offset_base, unsigned int IFDlength, unsigned int displacement, void * * *
tsrm_ls) Line 2789 C
php_exif.dll!exif_process_IFD_TAG(image_info_type * ImageInfo, char * dir_entry, char * offset_base,
unsigned int IFDlength, unsigned int displacement, int section_index, int ReadNextIFD, const
tag_info_type * tag_table, void * * * tsrm_ls) Line 3064 C
php_exif.dll!exif_process_IFD_in_JPEG(image_info_type * ImageInfo, char * dir_start, char *
offset_base, unsigned int IFDlength, unsigned int displacement, int section_index, void * * *
tsrm_ls) Line 3139 C
php_exif.dll!exif_process_IFD_TAG(image_info_type * ImageInfo, char * dir_entry, char * offset_base,
unsigned int IFDlength, unsigned int displacement, int section_index, int ReadNextIFD, const
tag_info_type * tag_table, void * * * tsrm_ls) Line 3101 C
php_exif.dll!exif_process_IFD_in_JPEG(image_info_type * ImageInfo, char * dir_start, char *
offset_base, unsigned int IFDlength, unsigned int displacement, int section_index, void * * *
tsrm_ls) Line 3139 C
php_exif.dll!exif_process_TIFF_in_JPEG(image_info_type * ImageInfo, char * CharBuf, unsigned int
length, unsigned int displacement, void * * * tsrm_ls) Line 3222 C
php_exif.dll!exif_process_APP1(image_info_type * ImageInfo, char * CharBuf, unsigned int length,
unsigned int displacement, void * * * tsrm_ls) Line 3240 C
php_exif.dll!exif_scan_JPEG_header(image_info_type * ImageInfo, void * * * tsrm_ls) Line 3426 C
php_exif.dll!exif_scan_FILE_header(image_info_type * ImageInfo, void * * * tsrm_ls) Line 3767 C
php_exif.dll!exif_read_file(image_info_type * ImageInfo, char * FileName, int read_thumbnail, int
read_all, void * * * tsrm_ls) Line 3908 C
php_exif.dll!zif_exif_read_data(int ht, _zval_struct * return_value, _zval_struct * *
return_value_ptr, _zval_struct * this_ptr, int return_value_used, void * * * tsrm_ls) Line 3960 C
------------------------------------------------------------------------
[2013-10-21 23:12:27] info at getid3 dot org
Problem exists for me in PHP 5.4.7 that I have installed here. Using the original poster's
sample code and sample file (or my own sample file linked above) Apache crashed with this in the
log:
[notice] Parent: child process exited with status 255 -- Restarting.
[notice] Apache/2.2.21 (Win32) PHP/5.4.7 configured -- resuming normal operations
------------------------------------------------------------------------
[2013-10-21 22:26:49] mike@php.net
Cannot reproduce with PHP-5.4+
------------------------------------------------------------------------
[2013-10-17 06:13:54] kbinaz at gmail dot com
Any update on this bug? I've also run into this same problem with using exif to read data from
some jpeg's. The script dies with a segmentation fault. I've applied Dominic's patch
manually and re-compiled, and it seems to fix the issue. Any eta on when it will make it to PHP
source?
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=62523
--
Edit this bug report at https://bugs.php.net/bug.php?id=62523&edit=1