Bug #67399 [Opn->Csd]: putenv with empty variable may lead to crash

From: Date: Mon, 09 Jun 2014 06:11:06 +0000
Subject: Bug #67399 [Opn->Csd]: putenv with empty variable may lead to crash
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-186113@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=67399&edit=1 ID: 67399 Updated by: stas@php.net Reported by: stas@php.net Summary: putenv with empty variable may lead to crash -Status: Open +Status: Closed Type: Bug Package: Reproducible crash Operating System: Unix PHP Version: 5.4.29 Block user comment: N Private report: N New Comment: Automatic comment on behalf of stas Revision: http://git.php.net/?p=php-src.git;a=commit;h=62857998c5f69aee1249db870b0fb08af9012fb9 Log: Fixed bug #67399 (putenv with empty variable may lead to crash) Previous Comments: ------------------------------------------------------------------------ [2014-06-09 05:53:19] stas@php.net Description: ------------ Report from Google team: putenv -> getenv SIGSEGV <?php // This script allocates some objects, making PHP reserve a memory region, // then sets an environment variable without any name ("=1234"). // // zif_putenv will add it to the environment, but when php_putenv_destructor is // called, at the end of the script, __unsetenv(name="") is called, which has // no effect and does *not* remove the pointer to the PHP-mapped memory region // in the environment table. // _efree and _zend_mm_free_int will free unmap the allocated PHP memory region // // zend_hash_apply_deleter -> module_destructor -> zm_shutdown_intl -> // -> __GI_getenv(name="INTL_EXPLICIT_CLEANUP") // will call C getenv() asking for a not-existing env variable to see if they // have to call ucleanup(). C getenv() will scan the corrupted environ and in: // // for (ep = __environ; &ep != NULL; ++ep) // // will access a freed memory region, segfaulting. error_reporting(E_ALL); set_time_limit(10); ini_set('memory_limit', '256M'); $x1 = "asdasdasfdsfdsf"; $x2 = "asdasdsadasdasdasd"; $x3 = array_fill(0, 553423, '*'); $x4 = array(-1 => -5, 100 => 17, 0 => 'a', 'a' => 0, 1 => 'b', 'b' => 1); $f = fopen('php://temp', 'wr'); putenv("=1234"); Test script: --------------- putenv("=1234"); ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=67399&edit=1

« previous php.bugs (#186113) next »