Bug #69551 [Ana]: parse_ini_file() and parse_ini_string() segmentation fault
| From: | cmb@php.net | Date: | Thu, 04 Jun 2015 00:54:46 +0000 |
| Subject: | Bug #69551 [Ana]: parse_ini_file() and parse_ini_string() segmentation fault | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-193099@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=69551&edit=1
ID: 69551
Updated by: cmb@php.net
Reported by: nystrom dot lars dot egon at gmail dot com
Summary: parse_ini_file() and parse_ini_string() segmentation
fault
Status: Analyzed
Type: Bug
Package: Filesystem function related
-Operating System: Linux
+Operating System: *
-PHP Version: 5.6.8
+PHP Version: 5.6.9
Block user comment: N
Private report: N
New Comment:
I have submitted a respective PR, what might accelerate the fix to
be merged. However, there are a lot of open PRs and the resources
to review them are limited, so please be patient.
If you really need the fix now, consider to compile PHP yourself,
applying the attached patch.
Previous Comments:
------------------------------------------------------------------------
[2015-06-03 07:28:43] nystrom dot lars dot egon at gmail dot com
This is still a pretty big issue for me, since there's no way to catch this error in PHP. When
can I expect this bug to be fixed?
------------------------------------------------------------------------
[2015-04-30 16:42:33] cmb@php.net
The escape character is actually irrelevant. The problem is a
linebreak immediately following a double-quote for a value. In
this case the ini scanner goes to end_raw_value_chars:[1] and
yyleng is set to 1. That causes
(yytext[0] == '"' && yytext[yyleng - 1] == '"')
to be true, and yyleng is decreased by 2. Thus a token with length
-1 is returned.
The solution is to avoid the above condition being true, when
there is only a single quote (the quote on the next line is
irrelevant, as the raw scanner does not allow linebreaks in
values). See the attached patch "raw-ini-scanner-segfault".
[1] <http://lxr.php.net/xref/PHP_TRUNK/Zend/zend_ini_scanner.l#518>
------------------------------------------------------------------------
[2015-04-30 16:40:52] cmb@php.net
The following patch has been added/updated:
Patch Name: raw-ini-scanner-segfault
Revision: 1430412052
URL: https://bugs.php.net/patch-display.php?bug=69551&patch=raw-ini-scanner-segfault&revision=1430412052
------------------------------------------------------------------------
[2015-04-30 13:35:50] nystrom dot lars dot egon at gmail dot com
Here's a better test script:
<?php
$a = '[Network.eth0]
SubnetMask = "' . "\x0A\x1B" . '"';
parse_ini_string($a, false, \INI_SCANNER_RAW);
------------------------------------------------------------------------
[2015-04-30 13:29:33] nystrom dot lars dot egon at gmail dot com
Description:
------------
This bug affects both parse_ini_file() and parse_ini_string().
If you try to parse a string which contains a line feed followed by an escape character PHP will
crash with a segmentation fault. This only happens when using the INI_SCANNER_RAW mode.
With "line feed followed by escape character" I mean two bytes with the following values:
0x0A 0x1B.
This affects all version of PHP I've tried: PHP 5.6.8, PHP 5.5.24 and PHP 5.3.29.
Test script:
---------------
<?php
$a = '[Network.eth0]
SubnetMask = "
"';
parse_ini_string($a, false, \INI_SCANNER_RAW);
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=69551&edit=1