Bug #67399 [NEW]: putenv with empty variable may lead to crash
| From: | stas@php.net | Date: | Mon, 09 Jun 2014 05:53:20 +0000 |
| Subject: | Bug #67399 [NEW]: putenv with empty variable may lead to crash | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-186111@lists.php.net to get a copy of this message | ||
From: stas
Operating system: Unix
PHP version: 5.4.29
Package: Reproducible crash
Bug Type: Bug
Bug description:putenv with empty variable may lead to crash
Description:
------------
Report from Google team:
putenv -> getenv SIGSEGV
<?php
// This script allocates some objects, making PHP reserve a memory
region,
// then sets an environment variable without any name ("=1234").
//
// zif_putenv will add it to the environment, but when
php_putenv_destructor is
// called, at the end of the script, __unsetenv(name="") is called,
which has
// no effect and does *not* remove the pointer to the PHP-mapped memory
region
// in the environment table.
// _efree and _zend_mm_free_int will free unmap the allocated PHP memory
region
//
// zend_hash_apply_deleter -> module_destructor -> zm_shutdown_intl ->
// -> __GI_getenv(name="INTL_EXPLICIT_CLEANUP")
// will call C getenv() asking for a not-existing env variable to see if
they
// have to call ucleanup(). C getenv() will scan the corrupted environ
and in:
//
// for (ep = __environ; &ep != NULL; ++ep)
//
// will access a freed memory region, segfaulting.
error_reporting(E_ALL);
set_time_limit(10);
ini_set('memory_limit', '256M');
$x1 = "asdasdasfdsfdsf";
$x2 = "asdasdsadasdasdasd";
$x3 = array_fill(0, 553423, '*');
$x4 = array(-1 => -5, 100 => 17, 0 => 'a', 'a' => 0, 1 =>
'b', 'b' =>
1);
$f = fopen('php://temp', 'wr');
putenv("=1234");
Test script:
---------------
putenv("=1234");
--
Edit bug report at https://bugs.php.net/bug.php?id=67399&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=67399&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=67399&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=67399&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=67399&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=67399&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=67399&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=67399&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=67399&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=67399&r=support
Expected behavior: https://bugs.php.net/fix.php?id=67399&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=67399&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=67399&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=67399&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=67399&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=67399&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=67399&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=67399&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=67399&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=67399&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=67399&r=mysqlcfg