Bug #69551 [Opn->Ana]: parse_ini_file() and parse_ini_string() segmentation fault
| From: | cmb@php.net | Date: | Thu, 30 Apr 2015 16:42:33 +0000 |
| Subject: | Bug #69551 [Opn->Ana]: parse_ini_file() and parse_ini_string() segmentation fault | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-192432@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=69551&edit=1
ID: 69551
Updated by: cmb@php.net
Reported by: nystrom dot lars dot egon at gmail dot com
Summary: parse_ini_file() and parse_ini_string() segmentation
fault
-Status: Open
+Status: Analyzed
Type: Bug
Package: Filesystem function related
Operating System: Linux
PHP Version: 5.6.8
Block user comment: N
Private report: N
New Comment:
The escape character is actually irrelevant. The problem is a
linebreak immediately following a double-quote for a value. In
this case the ini scanner goes to end_raw_value_chars:[1] and
yyleng is set to 1. That causes
(yytext[0] == '"' && yytext[yyleng - 1] == '"')
to be true, and yyleng is decreased by 2. Thus a token with length
-1 is returned.
The solution is to avoid the above condition being true, when
there is only a single quote (the quote on the next line is
irrelevant, as the raw scanner does not allow linebreaks in
values). See the attached patch "raw-ini-scanner-segfault".
[1] <http://lxr.php.net/xref/PHP_TRUNK/Zend/zend_ini_scanner.l#518>
Previous Comments:
------------------------------------------------------------------------
[2015-04-30 16:40:52] cmb@php.net
The following patch has been added/updated:
Patch Name: raw-ini-scanner-segfault
Revision: 1430412052
URL: https://bugs.php.net/patch-display.php?bug=69551&patch=raw-ini-scanner-segfault&revision=1430412052
------------------------------------------------------------------------
[2015-04-30 13:35:50] nystrom dot lars dot egon at gmail dot com
Here's a better test script:
<?php
$a = '[Network.eth0]
SubnetMask = "' . "\x0A\x1B" . '"';
parse_ini_string($a, false, \INI_SCANNER_RAW);
------------------------------------------------------------------------
[2015-04-30 13:29:33] nystrom dot lars dot egon at gmail dot com
Description:
------------
This bug affects both parse_ini_file() and parse_ini_string().
If you try to parse a string which contains a line feed followed by an escape character PHP will
crash with a segmentation fault. This only happens when using the INI_SCANNER_RAW mode.
With "line feed followed by escape character" I mean two bytes with the following values:
0x0A 0x1B.
This affects all version of PHP I've tried: PHP 5.6.8, PHP 5.5.24 and PHP 5.3.29.
Test script:
---------------
<?php
$a = '[Network.eth0]
SubnetMask = "
"';
parse_ini_string($a, false, \INI_SCANNER_RAW);
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=69551&edit=1