Bug #66339 [Asn]: PHP segfaults in imagexbm
| From: | krakjoe@php.net | Date: | Sun, 29 Dec 2013 09:54:02 +0000 |
| Subject: | Bug #66339 [Asn]: PHP segfaults in imagexbm | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-183480@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=66339&edit=1
ID: 66339
Updated by: krakjoe@php.net
Reported by: fernando at null-life dot com
Summary: PHP segfaults in imagexbm
Status: Assigned
Type: Bug
Package: GD related
Operating System: Windows
PHP Version: 5.5.7
Assigned To: helly
Block user comment: N
Private report: N
New Comment:
Assigned to the person who wrote the source, hopefully they'll have some insight ...
Previous Comments:
------------------------------------------------------------------------
[2013-12-23 06:14:44] fernando at null-life dot com
Description:
------------
I noticed a couple of wrongdoings (according to docs) in this imagexbm function:
- When passing null to the 2nd parameter (filename) PHP crashes.
- When passing a filename, the output stream is still sent to stdout.
http://www.php.net/manual/en/function.imagexbm.php
Test script:
---------------
<?php
$im = imagecreatetruecolor(20, 20);
imagexbm($im, null);
Expected result:
----------------
Show image on stdout since filename is null.
Actual result:
--------------
(940.b24): Access violation - code c0000005 (first chance)
First chance exceptions are reported before any exception handling.
This exception may be expected and handled.
eax=ffffffff ebx=00000000 ecx=00000000 edx=00000000 esi=00000000 edi=00000000
eip=6ba09262 esp=00a6e604 ebp=00a6e608 iopl=0 nv up ei pl zr na pe nc
cs=0023 ss=002b ds=002b es=002b fs=0053 gs=002b efl=00210246
MSVCR110!strrchr+0x3d:
6ba09262 f30f6f0f movdqu xmm1,xmmword ptr [edi]
ds:002b:00000000=????????????????????????????????
0:000> k
ChildEBP RetAddr
00a6e608 695eed56 MSVCR110!strrchr+0x3d
00a6e630 695d2933 php_gd2!php_gd_gdImageXbmCtx+0x16
[c:\php-sdk\php55\vc11\x86\php-5.5.7\ext\gd\libgd\xbm.c @ 181]
00a6e678 695d7ba8 php_gd2!_php_image_output_ctx+0x283
[c:\php-sdk\php55\vc11\x86\php-5.5.7\ext\gd\gd_ctx.c @ 171]
00a6e694 67c49971 php_gd2!zif_imagexbm+0x18 [c:\php-sdk\php55\vc11\x86\php-5.5.7\ext\gd\gd.c @ 2696]
00a6e6fc 67c49075 php5!zend_do_fcall_common_helper_SPEC+0x1b1
[c:\php-sdk\php55\vc11\x86\php-5.5.7\zend\zend_vm_execute.h @ 550]
00a6e738 67c6052b php5!execute_ex+0x295 [c:\php-sdk\php55\vc11\x86\php-5.5.7\zend\zend_vm_execute.h
@ 363]
00a6e75c 67c60ede php5!zend_execute+0x14b
[c:\php-sdk\php55\vc11\x86\php-5.5.7\zend\zend_vm_execute.h @ 388]
00a6e790 67c61c7c php5!zend_execute_scripts+0xde [c:\php-sdk\php55\vc11\x86\php-5.5.7\zend\zend.c @
1320]
00a6ea20 7749a1e0 php5!php_execute_script+0x14c [c:\php-sdk\php55\vc11\x86\php-5.5.7\main\main.c @
2489]
00a6ea34 7749aa22 KERNELBASE!BasepInitializeFindFileHandle+0x59
00a6ed20 00a6ee1c KERNELBASE!FindFirstFileExW+0x532
WARNING: Frame IP not in any known module. Following frames may be wrong.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=66339&edit=1