Bug #69551 [Ana]: parse_ini_file() and parse_ini_string() segmentation fault

From: Date: Wed, 03 Jun 2015 07:28:43 +0000
Subject: Bug #69551 [Ana]: parse_ini_file() and parse_ini_string() segmentation fault
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-193081@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=69551&edit=1 ID: 69551 User updated by: nystrom dot lars dot egon at gmail dot com Reported by: nystrom dot lars dot egon at gmail dot com Summary: parse_ini_file() and parse_ini_string() segmentation fault Status: Analyzed Type: Bug Package: Filesystem function related Operating System: Linux PHP Version: 5.6.8 Block user comment: N Private report: N New Comment: This is still a pretty big issue for me, since there's no way to catch this error in PHP. When can I expect this bug to be fixed? Previous Comments: ------------------------------------------------------------------------ [2015-04-30 16:42:33] cmb@php.net The escape character is actually irrelevant. The problem is a linebreak immediately following a double-quote for a value. In this case the ini scanner goes to end_raw_value_chars:[1] and yyleng is set to 1. That causes (yytext[0] == '"' && yytext[yyleng - 1] == '"') to be true, and yyleng is decreased by 2. Thus a token with length -1 is returned. The solution is to avoid the above condition being true, when there is only a single quote (the quote on the next line is irrelevant, as the raw scanner does not allow linebreaks in values). See the attached patch "raw-ini-scanner-segfault". [1] <http://lxr.php.net/xref/PHP_TRUNK/Zend/zend_ini_scanner.l#518> ------------------------------------------------------------------------ [2015-04-30 16:40:52] cmb@php.net The following patch has been added/updated: Patch Name: raw-ini-scanner-segfault Revision: 1430412052 URL: https://bugs.php.net/patch-display.php?bug=69551&patch=raw-ini-scanner-segfault&revision=1430412052 ------------------------------------------------------------------------ [2015-04-30 13:35:50] nystrom dot lars dot egon at gmail dot com Here's a better test script: <?php $a = '[Network.eth0] SubnetMask = "' . "\x0A\x1B" . '"'; parse_ini_string($a, false, \INI_SCANNER_RAW); ------------------------------------------------------------------------ [2015-04-30 13:29:33] nystrom dot lars dot egon at gmail dot com Description: ------------ This bug affects both parse_ini_file() and parse_ini_string(). If you try to parse a string which contains a line feed followed by an escape character PHP will crash with a segmentation fault. This only happens when using the INI_SCANNER_RAW mode. With "line feed followed by escape character" I mean two bytes with the following values: 0x0A 0x1B. This affects all version of PHP I've tried: PHP 5.6.8, PHP 5.5.24 and PHP 5.3.29. Test script: --------------- <?php $a = '[Network.eth0] SubnetMask = " "'; parse_ini_string($a, false, \INI_SCANNER_RAW); ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=69551&edit=1

« previous php.bugs (#193081) next »