Bug #69551 [Ana->Csd]: parse_ini_file() and parse_ini_string() segmentation fault

From: Date: Wed, 10 Jun 2015 20:23:45 +0000
Subject: Bug #69551 [Ana->Csd]: parse_ini_file() and parse_ini_string() segmentation fault
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-193317@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=69551&edit=1 ID: 69551 Updated by: cmb@php.net Reported by: nystrom dot lars dot egon at gmail dot com Summary: parse_ini_file() and parse_ini_string() segmentation fault -Status: Analyzed +Status: Closed Type: Bug Package: Filesystem function related Operating System: * PHP Version: 5.6.9 -Assigned To: +Assigned To: cmb Block user comment: N Private report: N New Comment: The fix for this bug has been committed. Thank you for the report, and for helping us make PHP better. Previous Comments: ------------------------------------------------------------------------ [2015-06-04 00:54:46] cmb@php.net I have submitted a respective PR, what might accelerate the fix to be merged. However, there are a lot of open PRs and the resources to review them are limited, so please be patient. If you really need the fix now, consider to compile PHP yourself, applying the attached patch. ------------------------------------------------------------------------ [2015-06-03 07:28:43] nystrom dot lars dot egon at gmail dot com This is still a pretty big issue for me, since there's no way to catch this error in PHP. When can I expect this bug to be fixed? ------------------------------------------------------------------------ [2015-04-30 16:42:33] cmb@php.net The escape character is actually irrelevant. The problem is a linebreak immediately following a double-quote for a value. In this case the ini scanner goes to end_raw_value_chars:[1] and yyleng is set to 1. That causes (yytext[0] == '"' && yytext[yyleng - 1] == '"') to be true, and yyleng is decreased by 2. Thus a token with length -1 is returned. The solution is to avoid the above condition being true, when there is only a single quote (the quote on the next line is irrelevant, as the raw scanner does not allow linebreaks in values). See the attached patch "raw-ini-scanner-segfault". [1] <http://lxr.php.net/xref/PHP_TRUNK/Zend/zend_ini_scanner.l#518> ------------------------------------------------------------------------ [2015-04-30 16:40:52] cmb@php.net The following patch has been added/updated: Patch Name: raw-ini-scanner-segfault Revision: 1430412052 URL: https://bugs.php.net/patch-display.php?bug=69551&patch=raw-ini-scanner-segfault&revision=1430412052 ------------------------------------------------------------------------ [2015-04-30 13:35:50] nystrom dot lars dot egon at gmail dot com Here's a better test script: <?php $a = '[Network.eth0] SubnetMask = "' . "\x0A\x1B" . '"'; parse_ini_string($a, false, \INI_SCANNER_RAW); ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=69551 -- Edit this bug report at https://bugs.php.net/bug.php?id=69551&edit=1

« previous php.bugs (#193317) next »