Edit report at https://bugs.php.net/bug.php?id=62523&edit=1
ID: 62523
Comment by: ken at boingboing dot net
Reported by: bigbug at mafia dot lv
Summary: php crashes with segfault when exif_read_data called
Status: No Feedback
Type: Bug
Package: Reproducible crash
Operating System: linux
PHP Version: 5.3Git-2012-07-10 (snap)
Assigned To: rasmus
Block user comment: N
Private report: N
New Comment:
We're experiencing the same issue.
Any attempt to import this post into wordpress generated the same issue when it calles
exif_read_date (for reference, wp-admin/includes/image.php, line 339):
$exif = @exif_read_data( $file );
Removing the EXIF data eliminates the issue.
Previous Comments:
------------------------------------------------------------------------
[2014-12-30 10:41:51] php-bugs at lists dot php dot net
No feedback was provided. The bug is being suspended because
we assume that you are no longer experiencing the problem.
If this is not the case and you are able to provide the
information that was requested earlier, please do so and
change the status of the bug back to "Re-Opened". Thank you.
------------------------------------------------------------------------
[2013-11-17 07:28:21] sdrinf at gmail dot com
I'm the one being assisted by nbishop; specific circumstances were:
* 32-bit ubuntu 10.04 , 32-bit custom-compiled PHP 5.5.5
* Unit test were called from CLI, consisted of a single exif_read_data command
* Crashing image can be found at http://178.79.135.16/static/segfault_image.jpg
* Crash repros 100% of the time.
After burning a handful of hours on this, I've worked around by nuking the VPS, and installing
a 64-bit 12.04 Ubuntu. This failed to repro segfault on this, or any of the images attached above
(yay).
------------------------------------------------------------------------
[2013-11-17 05:08:25] me at nbishop dot name
After trying to assist someone with this issue on their setup I decided to test it some on mine
since the reports of it's existence are pretty varied.
Out of four images tested (one the person provided, and the three linked here), only ONE of the
images actually caused a segfault on both of my two tested setups, and that was the bad_exif.jpeg
file.
My two setups are a 5.4.14 source-compiled on a 32-bit Fedora 17, and a 5.4.20 source-compiled on a
64-bit Fedora 19, and as noted above none of the images EXCEPT the bad_exif.jpeg cause segfaults
under either web access (lighttpd+php-fpm setup) or CLI called.
Rebuilt the 5.4.14 setup into debug to get the following;
(gdb) bt
#0 0x0831ecfc in mbfl_buffer_converter_new2 (from=0x8a4f790, to=0x0,
buf_initsz=38)
at /root/apps/php-5.4.14/ext/mbstring/libmbfl/mbfl/mbfilter.c:158
#1 0x08326684 in php_mb_zend_encoding_converter (to=0xbfffbeec,
to_length=0xbfffb9c4, from=0xb765aa1e "", from_length=38, encoding_to=0x0,
encoding_from=0x8a4f790)
at /root/apps/php-5.4.14/ext/mbstring/mbstring.c:917
#2 0x0861feeb in zend_multibyte_encoding_converter (to=0xbfffbeec,
to_length=0xbfffb9c4, from=0xb765aa1e "", from_length=38, encoding_to=0x0,
encoding_from=0x8a4f790) at /root/apps/php-5.4.14/Zend/zend_multibyte.c:150
#3 0x082264ba in exif_process_user_comment (ImageInfo=0xbfffbe98,
pszInfoPtr=0xbfffbeec, pszEncoding=0xbfffbef4, szValuePtr=0xb765aa1e "",
ByteCount=38) at /root/apps/php-5.4.14/ext/exif/exif.c:2666
#4 0x08227270 in exif_process_IFD_TAG (ImageInfo=0xbfffbe98,
dir_entry=0xb765a93a "\206\222\a", offset_base=0xb765a780 "II*",
IFDlength=24564, displacement=12, section_index=7, ReadNextIFD=1,
tag_table=0x8747f60) at /root/apps/php-5.4.14/ext/exif/exif.c:2972
#5 0x08227953 in exif_process_IFD_in_JPEG (ImageInfo=0xbfffbe98,
dir_start=0xb765a86c "\031", offset_base=0xb765a780 "II*",
IFDlength=24564, displacement=12, section_index=7)
at /root/apps/php-5.4.14/ext/exif/exif.c:3138
#6 0x0822776f in exif_process_IFD_TAG (ImageInfo=0xbfffbe98,
dir_entry=0xb765a7f6 "i\207\004", offset_base=0xb765a780 "II*",
IFDlength=24564, displacement=12, section_index=3, ReadNextIFD=1,
tag_table=0x8747f60) at /root/apps/php-5.4.14/ext/exif/exif.c:3101
#7 0x08227953 in exif_process_IFD_in_JPEG (ImageInfo=0xbfffbe98,
dir_start=0xb765a788 "\n", offset_base=0xb765a780 "II*", IFDlength=24564,
displacement=12, section_index=3)
at /root/apps/php-5.4.14/ext/exif/exif.c:3138
#8 0x08227c06 in exif_process_TIFF_in_JPEG (ImageInfo=0xbfffbe98,
CharBuf=0xb765a780 "II*", length=24564, displacement=12)
at /root/apps/php-5.4.14/ext/exif/exif.c:3215
#9 0x08227ccc in exif_process_APP1 (ImageInfo=0xbfffbe98,
CharBuf=0xb765a778 "_\374Exif", length=24572, displacement=4)
at /root/apps/php-5.4.14/ext/exif/exif.c:3240
#10 0x08228235 in exif_scan_JPEG_header (ImageInfo=0xbfffbe98)
at /root/apps/php-5.4.14/ext/exif/exif.c:3385
#11 0x0822906e in exif_scan_FILE_header (ImageInfo=0xbfffbe98)
at /root/apps/php-5.4.14/ext/exif/exif.c:3767
#12 0x08229bd8 in exif_read_file (ImageInfo=0xbfffbe98,
FileName=0xb756af78 "/home/www/sites/bad_exif.jpeg", read_thumbnail=0,
read_all=0) at /root/apps/php-5.4.14/ext/exif/exif.c:3906
#13 0x08229db4 in zif_exif_read_data (ht=1, return_value=0xb7656d08,
return_value_ptr=0x0, this_ptr=0x0, return_value_used=1)
at /root/apps/php-5.4.14/ext/exif/exif.c:3959
#14 0x0863a1d6 in zend_do_fcall_common_helper_SPEC (execute_data=0xb763c074)
at /root/apps/php-5.4.14/Zend/zend_vm_execute.h:643
#15 0x0863db9d in ZEND_DO_FCALL_SPEC_CONST_HANDLER (execute_data=0xb763c074)
at /root/apps/php-5.4.14/Zend/zend_vm_execute.h:2225
#16 0x086398bf in execute (op_array=0xb76574e8)
at /root/apps/php-5.4.14/Zend/zend_vm_execute.h:410
#17 0x0860708e in zend_execute_scripts (type=8, retval=0x0, file_count=3)
at /root/apps/php-5.4.14/Zend/zend.c:1315
#18 0x085910cf in php_execute_script (primary_file=0xbffff434)
at /root/apps/php-5.4.14/main/main.c:2492
#19 0x08698b2b in do_cli (argc=2, argv=0xbffff6a4)
at /root/apps/php-5.4.14/sapi/cli/php_cli.c:988
#20 0x08699c01 in main (argc=2, argv=0xbffff6a4)
at /root/apps/php-5.4.14/sapi/cli/php_cli.c:1364
------------------------------------------------------------------------
[2013-10-23 01:25:48] kbinaz at gmail dot com
To expand on my last comment, the patch from Dominic fixed the SegFault, but caused other issues
with reading the majority of the exif data. I was no longer able to read other meta-data including
Orientation, and had to revert.
Here are some of the details from my setup:
CentOS 5.9 x86_64
PHP 5.5.4
- File -
<?
$array = exif_read_data('file.jpg');
print_r($array);
exit;
?>
- Output -
php test.php
PHP Warning: exif_read_data(file.jpg): Incorrect APP1 Exif Identifier Code in
/home/xoticspottest/site/test.php on line 2
Segmentation fault
- Strace php test.php -
...
read(3, "\377\330\377\340\0\20JFIF\0\1\1\1\0H\0H\0\0\377\341\v\273http://n"..., 8192) = 8192
write(2, "PHP Warning: exif_read_data(101"..., 140PHP Warning: exif_read_data(file.jpg):
Incorrect APP1 Exif Identifier Code in /home/xoticspottest/site/test.php on line 2) = 140
read(3, "\0^\17\0\0\230\0\3\0\4\0\0\0^\23\0\0\231\0\4\0J\0\0\0f\23\0\0\232\0\4"..., 8192)
= 8192
read(3, "\1\3\21\1\377\304\0\37\0\0\1\5\1\1\1\1\1\1\0\0\0\0\0\0\0\0\1\2\3\4\5\6"..., 8192)
= 8192
mmap(NULL, 266240, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x2acd7c444000
mmap(NULL, 266240, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x2acd7c485000
close(3) = 0
mmap(NULL, 266240, PROT_READ|PROT_WRITE, MAP_PRIVATE|MAP_ANONYMOUS, -1, 0) = 0x2acd7c4c6000
--- SIGSEGV (Segmentation fault) @ 0 (0) ---
+++ killed by SIGSEGV +++
If needed, email me for the sample jpg. I can't put it on a public URL due to licensing issues.
------------------------------------------------------------------------
[2013-10-22 13:22:19] glen at delfi dot ee
please note that this patch makes 64bit platforms crash due misuse of int (4 bytes) vs size_t
(8bytes)
https://code.google.com/p/php52-backports/issues/detail?id=36
attaching fix to that ticket there
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=62523
--
Edit this bug report at https://bugs.php.net/bug.php?id=62523&edit=1