Bug #66095 [Com]: Bundled libmagic has public symbols and conflicts with system libmagic

From: Date: Sun, 28 Dec 2014 13:55:06 +0000
Subject: Bug #66095 [Com]: Bundled libmagic has public symbols and conflicts with system libmagic
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-189241@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=66095&edit=1 ID: 66095 Comment by: rossi dot f at inwind dot it Reported by: vitalif at mail dot ru Summary: Bundled libmagic has public symbols and conflicts with system libmagic Status: Open Type: Bug Package: Filesystem function related Operating System: Linux PHP Version: 5.5.6 Block user comment: N Private report: N New Comment: First of all I'm experiencing the same problem with my system, I'm using PHP 5.5.20 and apache 2.2.27 with an external libmagic (version 5.21). Up to now the only way to survive has been to keep the system libmagic at version 5.11 but this has implications on the secuiry! Is there any PHP developer thinking about how to solve this issue? I have tried to apply the patch here proposed but it doesn't seem to work because I get errors when compiling the code, see the attached log. Previous Comments: ------------------------------------------------------------------------ [2014-02-25 19:24:10] devurandom at gmx dot net See-Also: https://bugs.php.net/bug.php?id=54241 ------------------------------------------------------------------------ [2014-02-25 19:16:49] devurandom at gmx dot net I can reproduce this using PHP 5.5.9 on Apache 2.4.7. See-Also: https://github.com/jappix/jappix/issues/417 ------------------------------------------------------------------------ [2013-11-14 13:58:58] vitalif at mail dot ru Description: ------------ In the PHP fileinfo extension, there is a bundled libmagic with public symbols. So when the fileinfo extension is loaded (either as a shared object or when built into PHP itself) - it can conflict with system libmagic. The conflict appears when you have different system libmagic version, and when you load PHP module into Apache along with some other Apache module that uses libmagic, for example - mod_dav_svn (Subversion DAV server). The result depends on the loading order: * If libphp5.so (or fileinfo.so) is loaded first, then Subversion gets incorrect libmagic symbols and crashes * If mod_dav_svn is loaded first, then PHP fileinfo gets incorrect libmagic symbols and also crashes The bundled extension should have ALL libmagic symbols declared as static. It can be achieved via overriding 'public/protected' macros in libmagic code and including all libmagic sources into fileinfo.c instead of compiling and linking them separately. (See the attached patch) ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=66095&edit=1

« previous php.bugs (#189241) next »