Bug #66095 [Com]: Bundled libmagic has public symbols and conflicts with system libmagic
| From: | rossi dot f at inwind dot it | Date: | Sun, 28 Dec 2014 13:55:06 +0000 |
| Subject: | Bug #66095 [Com]: Bundled libmagic has public symbols and conflicts with system libmagic | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-189241@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=66095&edit=1
ID: 66095
Comment by: rossi dot f at inwind dot it
Reported by: vitalif at mail dot ru
Summary: Bundled libmagic has public symbols and conflicts
with system libmagic
Status: Open
Type: Bug
Package: Filesystem function related
Operating System: Linux
PHP Version: 5.5.6
Block user comment: N
Private report: N
New Comment:
First of all I'm experiencing the same problem with my system, I'm using PHP 5.5.20 and
apache 2.2.27 with an external libmagic (version 5.21). Up to now the only way to survive has been
to keep the system libmagic at version 5.11 but this has implications on the secuiry!
Is there any PHP developer thinking about how to solve this issue?
I have tried to apply the patch here proposed but it doesn't seem to work because I get errors
when compiling the code, see the attached log.
Previous Comments:
------------------------------------------------------------------------
[2014-02-25 19:24:10] devurandom at gmx dot net
See-Also: https://bugs.php.net/bug.php?id=54241
------------------------------------------------------------------------
[2014-02-25 19:16:49] devurandom at gmx dot net
I can reproduce this using PHP 5.5.9 on Apache 2.4.7.
See-Also: https://github.com/jappix/jappix/issues/417
------------------------------------------------------------------------
[2013-11-14 13:58:58] vitalif at mail dot ru
Description:
------------
In the PHP fileinfo extension, there is a bundled libmagic with public symbols.
So when the fileinfo extension is loaded (either as a shared object or when built into PHP itself) -
it can conflict with system libmagic.
The conflict appears when you have different system libmagic version, and when you load PHP module
into Apache along with some other Apache module that uses libmagic, for example - mod_dav_svn
(Subversion DAV server). The result depends on the loading order:
* If libphp5.so (or fileinfo.so) is loaded first, then Subversion gets incorrect libmagic symbols
and crashes
* If mod_dav_svn is loaded first, then PHP fileinfo gets incorrect libmagic symbols and also crashes
The bundled extension should have ALL libmagic symbols declared as static. It can be achieved via
overriding 'public/protected' macros in libmagic code and including all libmagic sources
into fileinfo.c instead of compiling and linking them separately. (See the attached patch)
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=66095&edit=1