Bug #69121 [NEW]: Segfault in get_current_user when script owner is not in passwd
From: dan at syneto dot net
Operating system:
PHP version: 5.6.6
Package: Reproducible crash
Bug Type: Bug
Bug description:Segfault in get_current_user when script owner is not in passwd
Description:
------------
This is a bug in function php_get_current_user (main.c) when compiling
in a standards compliant environment on Illumos or Solaris based
systems. It might also be happening on Linux or other Unix systems that
follow the below semantics of getpwuid.
This is the relevant section from the getpwnam_r() manual from Illumos:
=== (illumos) man getpwuid_r ===
...
The standard-conforming functions getpwnam_r() and getpwuid_r()
can
return 0 even on an error, particularly in the case where the
requested
entry is not found. The application needs to check the return
value and
that the pwd pointer is non-null. Otherwise, an error value is
returned
to indicate the error.
...
The same issue is pointed to by the equivalent section on Linux
systems:
=== (linux) man getpwuid_r ===
...
If no matching password record was found, these functions return
0 and store NULL in *result
...
When running the test script, make sure you are root and able to run
sudo to change its owner to a non-existent UID using:
$ sudo chown 31415 get_current_user.php
You will not need to run the script as root. Just make sure its owner
UID does not exist in /etc/passwd.
I also attached a patch that properly checks for a NULL result.
Test script:
---------------
=== First code:
<?php
echo "Owner: " . get_current_user() . "\n";
=== Second code:
<?php
array_fill(5, 6, 'banana');
echo "Owner: " . get_current_user() . "\n";
Expected result:
----------------
=== First code output:
Owner:
=== Second code output:
Owner:
Actual result:
--------------
=== First code output:
Owner: d��
=== Second code output:
Segmentation Fault (core dumped)
admin@vmbox-desk:/tmp/test$ pstack core
core 'core' of 8560: php ./get_current_user.php
fffffd7fff130474 strlen () + 14
000000000065df1b zif_get_current_user () + 2b
000000000072eb91 dtrace_execute_internal () + 91
00000000007f6e21 zend_do_fcall_common_helper_SPEC () + 661
000000000077d51b execute_ex () + 4b
000000000072ea6b dtrace_execute_ex () + 13b
00000000007442b2 zend_execute_scripts () + 1d2
00000000006d03af php_execute_script () + 1ef
00000000007f92cc do_cli () + 12bc
00000000008092aa main () + 63a
00000000004d8a7c _start () + 6c
--
Edit bug report at https://bugs.php.net/bug.php?id=69121&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=69121&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=69121&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=69121&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=69121&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=69121&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=69121&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=69121&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=69121&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=69121&r=support
Expected behavior: https://bugs.php.net/fix.php?id=69121&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=69121&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=69121&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=69121&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=69121&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=69121&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=69121&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=69121&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=69121&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=69121&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=69121&r=mysqlcfg
Thread (5 messages)
- dan at syneto dot net