Bug #67399 [Opn->Csd]: putenv with empty variable may lead to crash
| From: | stas@php.net | Date: | Mon, 09 Jun 2014 06:11:06 +0000 |
| Subject: | Bug #67399 [Opn->Csd]: putenv with empty variable may lead to crash | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-186113@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=67399&edit=1
ID: 67399
Updated by: stas@php.net
Reported by: stas@php.net
Summary: putenv with empty variable may lead to crash
-Status: Open
+Status: Closed
Type: Bug
Package: Reproducible crash
Operating System: Unix
PHP Version: 5.4.29
Block user comment: N
Private report: N
New Comment:
Automatic comment on behalf of stas
Revision: http://git.php.net/?p=php-src.git;a=commit;h=62857998c5f69aee1249db870b0fb08af9012fb9
Log: Fixed bug #67399 (putenv with empty variable may lead to crash)
Previous Comments:
------------------------------------------------------------------------
[2014-06-09 05:53:19] stas@php.net
Description:
------------
Report from Google team:
putenv -> getenv SIGSEGV
<?php
// This script allocates some objects, making PHP reserve a memory region,
// then sets an environment variable without any name ("=1234").
//
// zif_putenv will add it to the environment, but when php_putenv_destructor is
// called, at the end of the script, __unsetenv(name="") is called, which has
// no effect and does *not* remove the pointer to the PHP-mapped memory region
// in the environment table.
// _efree and _zend_mm_free_int will free unmap the allocated PHP memory region
//
// zend_hash_apply_deleter -> module_destructor -> zm_shutdown_intl ->
// -> __GI_getenv(name="INTL_EXPLICIT_CLEANUP")
// will call C getenv() asking for a not-existing env variable to see if they
// have to call ucleanup(). C getenv() will scan the corrupted environ and in:
//
// for (ep = __environ; &ep != NULL; ++ep)
//
// will access a freed memory region, segfaulting.
error_reporting(E_ALL);
set_time_limit(10);
ini_set('memory_limit', '256M');
$x1 = "asdasdasfdsfdsf";
$x2 = "asdasdsadasdasdasd";
$x3 = array_fill(0, 553423, '*');
$x4 = array(-1 => -5, 100 => 17, 0 => 'a', 'a' => 0, 1 =>
'b', 'b' => 1);
$f = fopen('php://temp', 'wr');
putenv("=1234");
Test script:
---------------
putenv("=1234");
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=67399&edit=1