Bug #69224 [Opn]: Fileinfo tries to allocate huge amounts of memory for some text files

From: Date: Thu, 12 Mar 2015 04:22:35 +0000
Subject: Bug #69224 [Opn]: Fileinfo tries to allocate huge amounts of memory for some text files
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-191336@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=69224&edit=1

 ID:                 69224
 Updated by:         laruence@php.net
 Reported by:        john at zerocrates dot org
 Summary:            Fileinfo tries to allocate huge amounts of memory
                     for some text files
 Status:             Open
 Type:               Bug
 Package:            Filesystem function related
 Operating System:   Linux
 PHP Version:        5.6.6
-Assigned To:        
+Assigned To:        ab
 Block user comment: N
 Private report:     N

 New Comment:

this is a knew issue, as I remebered welting said about considering update libmagic to fix this.

@welting, any comments?


Previous Comments:
------------------------------------------------------------------------
[2015-03-11 20:30:36] aharvey@php.net

Pretty sure this is a duplicate of bug #68819 — can someone with security access check that,
please?

------------------------------------------------------------------------
[2015-03-11 20:29:19] john at zerocrates dot org

Just to clarify, the test file "test.csv" is only 28 kilobytes, nowhere near the memory
limit or the requested allocation size.

------------------------------------------------------------------------
[2015-03-11 20:27:08] john at zerocrates dot org

Description:
------------
When run on certain files (chiefly text files and in this specific instance, CSV files), the
Fileinfo extension immediately tries to allocate a huge amount of memory (multiple gigabytes) and
exceeds the limit.

This behavior on a sample file was confirmed on multiple PHP versions across different
distributions, including PHP 5.4.36 on CentOS (with "file" version 5.04) and PHP 5.6.6 on
Gentoo (with "file" version 5.22).

The file "test.csv" that causes this behavior is available at http://zerocrates.org/test.csv

Test script:
---------------
$finfo = finfo_open(FILEINFO_MIME_TYPE);
echo finfo_file($finfo, 'test.csv');

OR

$finfo = new finfo(FILEINFO_MIME_TYPE);
echo $finfo->file('test.csv');

Expected result:
----------------
The output should simply be "text/plain"

Running the command-line tool "file -bi" on the sample file gives a correct output more or
less immediately: "text/plain; charset=us-ascii"

Actual result:
--------------
Fatal error: Allowed memory size of 134217728 bytes exhausted (tried to allocate 4294955358 bytes)

Note the amount of bytes for the attempted allocation, 4 gigabytes.


------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=69224&edit=1


Thread (7 messages)

« previous php.bugs (#191336) next »