Edit report at https://bugs.php.net/bug.php?id=62523&edit=1
ID: 62523
Updated by: yohgaki@php.net
Reported by: bigbug at mafia dot lv
Summary: php crashes with segfault when exif_read_data called
-Status: No Feedback
+Status: Feedback
Type: Bug
Package: Reproducible crash
Operating System: linux
PHP Version: 5.3Git-2012-07-10 (snap)
Assigned To: rasmus
Block user comment: N
Private report: N
New Comment:
Please describe your environment. The offending file is needed. could you upload them somewhere and
link it?
Previous Comments:
------------------------------------------------------------------------
[2015-02-10 00:04:29] stephane dot boisvert at automattic dot com
I helped debug the issue for BoingBoing regarding exif_read_data() causing a segfault.
This was on RHEL 6 PHP 5.4
------------------------------------------------------------------------
[2015-02-09 22:09:11] ken at boingboing dot net
We're experiencing the same issue.
Any attempt to import this post into wordpress generated the same issue when it calles
exif_read_date (for reference, wp-admin/includes/image.php, line 339):
$exif = @exif_read_data( $file );
Removing the EXIF data eliminates the issue.
------------------------------------------------------------------------
[2014-12-30 10:41:51] php-bugs at lists dot php dot net
No feedback was provided. The bug is being suspended because
we assume that you are no longer experiencing the problem.
If this is not the case and you are able to provide the
information that was requested earlier, please do so and
change the status of the bug back to "Re-Opened". Thank you.
------------------------------------------------------------------------
[2013-11-17 07:28:21] sdrinf at gmail dot com
I'm the one being assisted by nbishop; specific circumstances were:
* 32-bit ubuntu 10.04 , 32-bit custom-compiled PHP 5.5.5
* Unit test were called from CLI, consisted of a single exif_read_data command
* Crashing image can be found at http://178.79.135.16/static/segfault_image.jpg
* Crash repros 100% of the time.
After burning a handful of hours on this, I've worked around by nuking the VPS, and installing
a 64-bit 12.04 Ubuntu. This failed to repro segfault on this, or any of the images attached above
(yay).
------------------------------------------------------------------------
[2013-11-17 05:08:25] me at nbishop dot name
After trying to assist someone with this issue on their setup I decided to test it some on mine
since the reports of it's existence are pretty varied.
Out of four images tested (one the person provided, and the three linked here), only ONE of the
images actually caused a segfault on both of my two tested setups, and that was the bad_exif.jpeg
file.
My two setups are a 5.4.14 source-compiled on a 32-bit Fedora 17, and a 5.4.20 source-compiled on a
64-bit Fedora 19, and as noted above none of the images EXCEPT the bad_exif.jpeg cause segfaults
under either web access (lighttpd+php-fpm setup) or CLI called.
Rebuilt the 5.4.14 setup into debug to get the following;
(gdb) bt
#0 0x0831ecfc in mbfl_buffer_converter_new2 (from=0x8a4f790, to=0x0,
buf_initsz=38)
at /root/apps/php-5.4.14/ext/mbstring/libmbfl/mbfl/mbfilter.c:158
#1 0x08326684 in php_mb_zend_encoding_converter (to=0xbfffbeec,
to_length=0xbfffb9c4, from=0xb765aa1e "", from_length=38, encoding_to=0x0,
encoding_from=0x8a4f790)
at /root/apps/php-5.4.14/ext/mbstring/mbstring.c:917
#2 0x0861feeb in zend_multibyte_encoding_converter (to=0xbfffbeec,
to_length=0xbfffb9c4, from=0xb765aa1e "", from_length=38, encoding_to=0x0,
encoding_from=0x8a4f790) at /root/apps/php-5.4.14/Zend/zend_multibyte.c:150
#3 0x082264ba in exif_process_user_comment (ImageInfo=0xbfffbe98,
pszInfoPtr=0xbfffbeec, pszEncoding=0xbfffbef4, szValuePtr=0xb765aa1e "",
ByteCount=38) at /root/apps/php-5.4.14/ext/exif/exif.c:2666
#4 0x08227270 in exif_process_IFD_TAG (ImageInfo=0xbfffbe98,
dir_entry=0xb765a93a "\206\222\a", offset_base=0xb765a780 "II*",
IFDlength=24564, displacement=12, section_index=7, ReadNextIFD=1,
tag_table=0x8747f60) at /root/apps/php-5.4.14/ext/exif/exif.c:2972
#5 0x08227953 in exif_process_IFD_in_JPEG (ImageInfo=0xbfffbe98,
dir_start=0xb765a86c "\031", offset_base=0xb765a780 "II*",
IFDlength=24564, displacement=12, section_index=7)
at /root/apps/php-5.4.14/ext/exif/exif.c:3138
#6 0x0822776f in exif_process_IFD_TAG (ImageInfo=0xbfffbe98,
dir_entry=0xb765a7f6 "i\207\004", offset_base=0xb765a780 "II*",
IFDlength=24564, displacement=12, section_index=3, ReadNextIFD=1,
tag_table=0x8747f60) at /root/apps/php-5.4.14/ext/exif/exif.c:3101
#7 0x08227953 in exif_process_IFD_in_JPEG (ImageInfo=0xbfffbe98,
dir_start=0xb765a788 "\n", offset_base=0xb765a780 "II*", IFDlength=24564,
displacement=12, section_index=3)
at /root/apps/php-5.4.14/ext/exif/exif.c:3138
#8 0x08227c06 in exif_process_TIFF_in_JPEG (ImageInfo=0xbfffbe98,
CharBuf=0xb765a780 "II*", length=24564, displacement=12)
at /root/apps/php-5.4.14/ext/exif/exif.c:3215
#9 0x08227ccc in exif_process_APP1 (ImageInfo=0xbfffbe98,
CharBuf=0xb765a778 "_\374Exif", length=24572, displacement=4)
at /root/apps/php-5.4.14/ext/exif/exif.c:3240
#10 0x08228235 in exif_scan_JPEG_header (ImageInfo=0xbfffbe98)
at /root/apps/php-5.4.14/ext/exif/exif.c:3385
#11 0x0822906e in exif_scan_FILE_header (ImageInfo=0xbfffbe98)
at /root/apps/php-5.4.14/ext/exif/exif.c:3767
#12 0x08229bd8 in exif_read_file (ImageInfo=0xbfffbe98,
FileName=0xb756af78 "/home/www/sites/bad_exif.jpeg", read_thumbnail=0,
read_all=0) at /root/apps/php-5.4.14/ext/exif/exif.c:3906
#13 0x08229db4 in zif_exif_read_data (ht=1, return_value=0xb7656d08,
return_value_ptr=0x0, this_ptr=0x0, return_value_used=1)
at /root/apps/php-5.4.14/ext/exif/exif.c:3959
#14 0x0863a1d6 in zend_do_fcall_common_helper_SPEC (execute_data=0xb763c074)
at /root/apps/php-5.4.14/Zend/zend_vm_execute.h:643
#15 0x0863db9d in ZEND_DO_FCALL_SPEC_CONST_HANDLER (execute_data=0xb763c074)
at /root/apps/php-5.4.14/Zend/zend_vm_execute.h:2225
#16 0x086398bf in execute (op_array=0xb76574e8)
at /root/apps/php-5.4.14/Zend/zend_vm_execute.h:410
#17 0x0860708e in zend_execute_scripts (type=8, retval=0x0, file_count=3)
at /root/apps/php-5.4.14/Zend/zend.c:1315
#18 0x085910cf in php_execute_script (primary_file=0xbffff434)
at /root/apps/php-5.4.14/main/main.c:2492
#19 0x08698b2b in do_cli (argc=2, argv=0xbffff6a4)
at /root/apps/php-5.4.14/sapi/cli/php_cli.c:988
#20 0x08699c01 in main (argc=2, argv=0xbffff6a4)
at /root/apps/php-5.4.14/sapi/cli/php_cli.c:1364
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=62523
--
Edit this bug report at https://bugs.php.net/bug.php?id=62523&edit=1