Bug #62523 [Com]: php crashes with segfault when exif_read_data called
| From: | me at nbishop dot name | Date: | Sun, 17 Nov 2013 05:08:27 +0000 |
| Subject: | Bug #62523 [Com]: php crashes with segfault when exif_read_data called | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-182786@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=62523&edit=1
ID: 62523
Comment by: me at nbishop dot name
Reported by: bigbug at mafia dot lv
Summary: php crashes with segfault when exif_read_data called
Status: Feedback
Type: Bug
Package: Reproducible crash
Operating System: linux
PHP Version: 5.3Git-2012-07-10 (snap)
Assigned To: rasmus
Block user comment: N
Private report: N
New Comment:
After trying to assist someone with this issue on their setup I decided to test it some on mine
since the reports of it's existence are pretty varied.
Out of four images tested (one the person provided, and the three linked here), only ONE of the
images actually caused a segfault on both of my two tested setups, and that was the bad_exif.jpeg
file.
My two setups are a 5.4.14 source-compiled on a 32-bit Fedora 17, and a 5.4.20 source-compiled on a
64-bit Fedora 19, and as noted above none of the images EXCEPT the bad_exif.jpeg cause segfaults
under either web access (lighttpd+php-fpm setup) or CLI called.
Rebuilt the 5.4.14 setup into debug to get the following;
(gdb) bt
#0 0x0831ecfc in mbfl_buffer_converter_new2 (from=0x8a4f790, to=0x0,
buf_initsz=38)
at /root/apps/php-5.4.14/ext/mbstring/libmbfl/mbfl/mbfilter.c:158
#1 0x08326684 in php_mb_zend_encoding_converter (to=0xbfffbeec,
to_length=0xbfffb9c4, from=0xb765aa1e "", from_length=38, encoding_to=0x0,
encoding_from=0x8a4f790)
at /root/apps/php-5.4.14/ext/mbstring/mbstring.c:917
#2 0x0861feeb in zend_multibyte_encoding_converter (to=0xbfffbeec,
to_length=0xbfffb9c4, from=0xb765aa1e "", from_length=38, encoding_to=0x0,
encoding_from=0x8a4f790) at /root/apps/php-5.4.14/Zend/zend_multibyte.c:150
#3 0x082264ba in exif_process_user_comment (ImageInfo=0xbfffbe98,
pszInfoPtr=0xbfffbeec, pszEncoding=0xbfffbef4, szValuePtr=0xb765aa1e "",
ByteCount=38) at /root/apps/php-5.4.14/ext/exif/exif.c:2666
#4 0x08227270 in exif_process_IFD_TAG (ImageInfo=0xbfffbe98,
dir_entry=0xb765a93a "\206\222\a", offset_base=0xb765a780 "II*",
IFDlength=24564, displacement=12, section_index=7, ReadNextIFD=1,
tag_table=0x8747f60) at /root/apps/php-5.4.14/ext/exif/exif.c:2972
#5 0x08227953 in exif_process_IFD_in_JPEG (ImageInfo=0xbfffbe98,
dir_start=0xb765a86c "\031", offset_base=0xb765a780 "II*",
IFDlength=24564, displacement=12, section_index=7)
at /root/apps/php-5.4.14/ext/exif/exif.c:3138
#6 0x0822776f in exif_process_IFD_TAG (ImageInfo=0xbfffbe98,
dir_entry=0xb765a7f6 "i\207\004", offset_base=0xb765a780 "II*",
IFDlength=24564, displacement=12, section_index=3, ReadNextIFD=1,
tag_table=0x8747f60) at /root/apps/php-5.4.14/ext/exif/exif.c:3101
#7 0x08227953 in exif_process_IFD_in_JPEG (ImageInfo=0xbfffbe98,
dir_start=0xb765a788 "\n", offset_base=0xb765a780 "II*", IFDlength=24564,
displacement=12, section_index=3)
at /root/apps/php-5.4.14/ext/exif/exif.c:3138
#8 0x08227c06 in exif_process_TIFF_in_JPEG (ImageInfo=0xbfffbe98,
CharBuf=0xb765a780 "II*", length=24564, displacement=12)
at /root/apps/php-5.4.14/ext/exif/exif.c:3215
#9 0x08227ccc in exif_process_APP1 (ImageInfo=0xbfffbe98,
CharBuf=0xb765a778 "_\374Exif", length=24572, displacement=4)
at /root/apps/php-5.4.14/ext/exif/exif.c:3240
#10 0x08228235 in exif_scan_JPEG_header (ImageInfo=0xbfffbe98)
at /root/apps/php-5.4.14/ext/exif/exif.c:3385
#11 0x0822906e in exif_scan_FILE_header (ImageInfo=0xbfffbe98)
at /root/apps/php-5.4.14/ext/exif/exif.c:3767
#12 0x08229bd8 in exif_read_file (ImageInfo=0xbfffbe98,
FileName=0xb756af78 "/home/www/sites/bad_exif.jpeg", read_thumbnail=0,
read_all=0) at /root/apps/php-5.4.14/ext/exif/exif.c:3906
#13 0x08229db4 in zif_exif_read_data (ht=1, return_value=0xb7656d08,
return_value_ptr=0x0, this_ptr=0x0, return_value_used=1)
at /root/apps/php-5.4.14/ext/exif/exif.c:3959
#14 0x0863a1d6 in zend_do_fcall_common_helper_SPEC (execute_data=0xb763c074)
at /root/apps/php-5.4.14/Zend/zend_vm_execute.h:643
#15 0x0863db9d in ZEND_DO_FCALL_SPEC_CONST_HANDLER (execute_data=0xb763c074)
at /root/apps/php-5.4.14/Zend/zend_vm_execute.h:2225
#16 0x086398bf in execute (op_array=0xb76574e8)
at /root/apps/php-5.4.14/Zend/zend_vm_execute.h:410
#17 0x0860708e in zend_execute_scripts (type=8, retval=0x0, file_count=3)
at /root/apps/php-5.4.14/Zend/zend.c:1315
#18 0x085910cf in php_execute_script (primary_file=0xbffff434)
at /root/apps/php-5.4.14/main/main.c:2492
#19 0x08698b2b in do_cli (argc=2, argv=0xbffff6a4)
at /root/apps/php-5.4.14/sapi/cli/php_cli.c:988
#20 0x08699c01 in main (argc=2, argv=0xbffff6a4)
at /root/apps/php-5.4.14/sapi/cli/php_cli.c:1364
Previous Comments:
------------------------------------------------------------------------
[2013-10-23 01:25:48] kbinaz at gmail dot com
To expand on my last comment, the patch from Dominic fixed the SegFault, but caused other issues
with reading the majority of the exif data. I was no longer able to read other meta-data including
Orientation, and had to revert.
Here are some of the details from my setup:
CentOS 5.9 x86_64
PHP 5.5.4
- File -
<?
$array = exif_read_data('file.jpg');
print_r($array);
exit;
?>
- Output -
php test.php
PHP Warning: exif_read_data(file.jpg): Incorrect APP1 Exif Identifier Code in
/home/xoticspottest/site/test.php on line 2
Segmentation fault
- Strace php test.php -
...
read(3, "\377\330\377\340\0\20JFIF\0\1\1\1\0H\0H\0\0\377\341\v\273http://n"..., 8192) = 8192
write(2, "PHP Warning: exif_read_data(101"..., 140PHP Warning: exif_read_data(file.jpg):
Incorrect APP1 Exif Identifier Code in /home/xoticspottest/site/test.php on line 2) = 140
read(3, "\0^\17\0\0\230\0\3\0\4\0\0\0^\23\0\0\231\0\4\0J\0\0\0f\23\0\0\232\0\4"..., 8192)
= 8192
read(3, "\1\3\21\1\377\304\0\37\0\0\1\5\1\1\1\1\1\1\0\0\0\0\0\0\0\0\1\2\3\4\5\6"..., 8192)
= 8192
mmap(NULL, 266240, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x2acd7c444000
mmap(NULL, 266240, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x2acd7c485000
close(3) = 0
mmap(NULL, 266240, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x2acd7c4c6000
--- SIGSEGV (Segmentation fault) @ 0 (0) ---
+++ killed by SIGSEGV +++
If needed, email me for the sample jpg. I can't put it on a public URL due to licensing issues.
------------------------------------------------------------------------
[2013-10-22 13:22:19] glen at delfi dot ee
please note that this patch makes 64bit platforms crash due misuse of int (4 bytes) vs size_t
(8bytes)
https://code.google.com/p/php52-backports/issues/detail?id=36
attaching fix to that ticket there
------------------------------------------------------------------------
[2013-10-22 05:10:40] pajoye@php.net
Same here, using latest 5.5 or snaps:
php_exif.dll!php_ifd_get16u(void * value, int motorola_intel) Line 1095 C
php_exif.dll!exif_iif_add_value(image_info_type * image_info, int section_index, char * name, int
tag, int format, int length, void * value, int motorola_intel, void * * * tsrm_ls) Line 1754 C
php_exif.dll!exif_process_IFD_TAG(image_info_type * ImageInfo, char * dir_entry, char * offset_base,
unsigned int IFDlength, unsigned int displacement, int section_index, int ReadNextIFD, const
tag_info_type * tag_table, void * * * tsrm_ls) Line 3111 C
php_exif.dll!exif_process_IFD_in_MAKERNOTE(image_info_type * ImageInfo, char * value_ptr, int
value_len, char * offset_base, unsigned int IFDlength, unsigned int displacement, void * * *
tsrm_ls) Line 2789 C
php_exif.dll!exif_process_IFD_TAG(image_info_type * ImageInfo, char * dir_entry, char * offset_base,
unsigned int IFDlength, unsigned int displacement, int section_index, int ReadNextIFD, const
tag_info_type * tag_table, void * * * tsrm_ls) Line 3064 C
php_exif.dll!exif_process_IFD_in_JPEG(image_info_type * ImageInfo, char * dir_start, char *
offset_base, unsigned int IFDlength, unsigned int displacement, int section_index, void * * *
tsrm_ls) Line 3139 C
php_exif.dll!exif_process_IFD_TAG(image_info_type * ImageInfo, char * dir_entry, char * offset_base,
unsigned int IFDlength, unsigned int displacement, int section_index, int ReadNextIFD, const
tag_info_type * tag_table, void * * * tsrm_ls) Line 3101 C
php_exif.dll!exif_process_IFD_in_JPEG(image_info_type * ImageInfo, char * dir_start, char *
offset_base, unsigned int IFDlength, unsigned int displacement, int section_index, void * * *
tsrm_ls) Line 3139 C
php_exif.dll!exif_process_TIFF_in_JPEG(image_info_type * ImageInfo, char * CharBuf, unsigned int
length, unsigned int displacement, void * * * tsrm_ls) Line 3222 C
php_exif.dll!exif_process_APP1(image_info_type * ImageInfo, char * CharBuf, unsigned int length,
unsigned int displacement, void * * * tsrm_ls) Line 3240 C
php_exif.dll!exif_scan_JPEG_header(image_info_type * ImageInfo, void * * * tsrm_ls) Line 3426 C
php_exif.dll!exif_scan_FILE_header(image_info_type * ImageInfo, void * * * tsrm_ls) Line 3767 C
php_exif.dll!exif_read_file(image_info_type * ImageInfo, char * FileName, int read_thumbnail, int
read_all, void * * * tsrm_ls) Line 3908 C
php_exif.dll!zif_exif_read_data(int ht, _zval_struct * return_value, _zval_struct * *
return_value_ptr, _zval_struct * this_ptr, int return_value_used, void * * * tsrm_ls) Line 3960 C
------------------------------------------------------------------------
[2013-10-21 23:12:27] info at getid3 dot org
Problem exists for me in PHP 5.4.7 that I have installed here. Using the original poster's
sample code and sample file (or my own sample file linked above) Apache crashed with this in the
log:
[notice] Parent: child process exited with status 255 -- Restarting.
[notice] Apache/2.2.21 (Win32) PHP/5.4.7 configured -- resuming normal operations
------------------------------------------------------------------------
[2013-10-21 22:26:49] mike@php.net
Cannot reproduce with PHP-5.4+
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=62523
--
Edit this bug report at https://bugs.php.net/bug.php?id=62523&edit=1