Bug #70667 [NEW]: strtr() causes invalid writes and a crashes
| From: | tony2001@php.net | Date: | Thu, 08 Oct 2015 11:05:15 +0000 |
| Subject: | Bug #70667 [NEW]: strtr() causes invalid writes and a crashes | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-196490@lists.php.net to get a copy of this message | ||
From: tony2001
Operating system:
PHP version: 7.0Git-2015-10-08 (Git)
Package: Strings related
Bug Type: Bug
Bug description:strtr() causes invalid writes and a crashes
Description:
------------
The test example causes invalid writes and a crash in
php_strtr_array().
It seems that the problem is in num_bitset allocation, it's too small to
store all the bits, which results in a buffer overflow.
Test script:
---------------
$a = array("{{language_id}}"=>"255",
"{{partner_name}}"=>"test1");
var_dump(strtr("Sign in to test1", $a));
Expected result:
----------------
.
Actual result:
--------------
==9676== Invalid read of size 8
==9676== at 0x5A4212: php_strtr_array (string.c:3029)
==9676== by 0x5A5EE7: zif_strtr (string.c:3493)
==9676== by 0x6CDD62: ZEND_DO_ICALL_SPEC_HANDLER
(zend_vm_execute.h:583)
==9676== by 0x6CD84C: execute_ex (zend_vm_execute.h:414)
==9676== by 0x6CD92E: zend_execute (zend_vm_execute.h:458)
==9676== by 0x671EFA: zend_execute_scripts (zend.c:1558)
==9676== by 0x5E68CF: php_execute_script (main.c:2525)
==9676== by 0x72EFD4: do_cli (php_cli.c:974)
==9676== by 0x72FE56: main (php_cli.c:1345)
==9676== Address 0x67a1730 is 0 bytes after a block of size 16 alloc'd
==9676== at 0x4C29110: malloc (in
/usr/lib64/valgrind/vgpreload_memcheck-amd64-linux.so)
==9676== by 0x63EF22: _emalloc (zend_alloc.c:2410)
==9676== by 0x63F298: _safe_emalloc (zend_alloc.c:2482)
==9676== by 0x63F3BB: _ecalloc (zend_alloc.c:2505)
==9676== by 0x5A40E3: php_strtr_array (string.c:3007)
==9676== by 0x5A5EE7: zif_strtr (string.c:3493)
==9676== by 0x6CDD62: ZEND_DO_ICALL_SPEC_HANDLER
(zend_vm_execute.h:583)
==9676== by 0x6CD84C: execute_ex (zend_vm_execute.h:414)
==9676== by 0x6CD92E: zend_execute (zend_vm_execute.h:458)
==9676== by 0x671EFA: zend_execute_scripts (zend.c:1558)
==9676== by 0x5E68CF: php_execute_script (main.c:2525)
==9676== by 0x72EFD4: do_cli (php_cli.c:974)
==9676== by 0x72FE56: main (php_cli.c:1345)
--
Edit bug report at https://bugs.php.net/bug.php?id=70667&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=70667&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=70667&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=70667&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=70667&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=70667&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=70667&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=70667&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=70667&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=70667&r=support
Expected behavior: https://bugs.php.net/fix.php?id=70667&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=70667&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=70667&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=70667&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=70667&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=70667&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=70667&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=70667&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=70667&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=70667&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=70667&r=mysqlcfg