Bug #70667 [NEW]: strtr() causes invalid writes and a crashes

From: Date: Thu, 08 Oct 2015 11:05:15 +0000
Subject: Bug #70667 [NEW]: strtr() causes invalid writes and a crashes
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-196490@lists.php.net to get a copy of this message
From: tony2001 Operating system: PHP version: 7.0Git-2015-10-08 (Git) Package: Strings related Bug Type: Bug Bug description:strtr() causes invalid writes and a crashes Description: ------------ The test example causes invalid writes and a crash in php_strtr_array(). It seems that the problem is in num_bitset allocation, it's too small to store all the bits, which results in a buffer overflow. Test script: --------------- $a = array("{{language_id}}"=>"255", "{{partner_name}}"=>"test1"); var_dump(strtr("Sign in to test1", $a)); Expected result: ---------------- . Actual result: -------------- ==9676== Invalid read of size 8 ==9676== at 0x5A4212: php_strtr_array (string.c:3029) ==9676== by 0x5A5EE7: zif_strtr (string.c:3493) ==9676== by 0x6CDD62: ZEND_DO_ICALL_SPEC_HANDLER (zend_vm_execute.h:583) ==9676== by 0x6CD84C: execute_ex (zend_vm_execute.h:414) ==9676== by 0x6CD92E: zend_execute (zend_vm_execute.h:458) ==9676== by 0x671EFA: zend_execute_scripts (zend.c:1558) ==9676== by 0x5E68CF: php_execute_script (main.c:2525) ==9676== by 0x72EFD4: do_cli (php_cli.c:974) ==9676== by 0x72FE56: main (php_cli.c:1345) ==9676== Address 0x67a1730 is 0 bytes after a block of size 16 alloc'd ==9676== at 0x4C29110: malloc (in /usr/lib64/valgrind/vgpreload_memcheck-amd64-linux.so) ==9676== by 0x63EF22: _emalloc (zend_alloc.c:2410) ==9676== by 0x63F298: _safe_emalloc (zend_alloc.c:2482) ==9676== by 0x63F3BB: _ecalloc (zend_alloc.c:2505) ==9676== by 0x5A40E3: php_strtr_array (string.c:3007) ==9676== by 0x5A5EE7: zif_strtr (string.c:3493) ==9676== by 0x6CDD62: ZEND_DO_ICALL_SPEC_HANDLER (zend_vm_execute.h:583) ==9676== by 0x6CD84C: execute_ex (zend_vm_execute.h:414) ==9676== by 0x6CD92E: zend_execute (zend_vm_execute.h:458) ==9676== by 0x671EFA: zend_execute_scripts (zend.c:1558) ==9676== by 0x5E68CF: php_execute_script (main.c:2525) ==9676== by 0x72EFD4: do_cli (php_cli.c:974) ==9676== by 0x72FE56: main (php_cli.c:1345) -- Edit bug report at https://bugs.php.net/bug.php?id=70667&edit=1 -- Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=70667&r=trysnapshot54 Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=70667&r=trysnapshot55 Try a snapshot (trunk): https://bugs.php.net/fix.php?id=70667&r=trysnapshottrunk Fixed in SVN: https://bugs.php.net/fix.php?id=70667&r=fixed Fixed in release: https://bugs.php.net/fix.php?id=70667&r=alreadyfixed Need backtrace: https://bugs.php.net/fix.php?id=70667&r=needtrace Need Reproduce Script: https://bugs.php.net/fix.php?id=70667&r=needscript Try newer version: https://bugs.php.net/fix.php?id=70667&r=oldversion Not developer issue: https://bugs.php.net/fix.php?id=70667&r=support Expected behavior: https://bugs.php.net/fix.php?id=70667&r=notwrong Not enough info: https://bugs.php.net/fix.php?id=70667&r=notenoughinfo Submitted twice: https://bugs.php.net/fix.php?id=70667&r=submittedtwice register_globals: https://bugs.php.net/fix.php?id=70667&r=globals PHP 4 support discontinued: https://bugs.php.net/fix.php?id=70667&r=php4 Daylight Savings: https://bugs.php.net/fix.php?id=70667&r=dst IIS Stability: https://bugs.php.net/fix.php?id=70667&r=isapi Install GNU Sed: https://bugs.php.net/fix.php?id=70667&r=gnused Floating point limitations: https://bugs.php.net/fix.php?id=70667&r=float No Zend Extensions: https://bugs.php.net/fix.php?id=70667&r=nozend MySQL Configuration Error: https://bugs.php.net/fix.php?id=70667&r=mysqlcfg

« previous php.bugs (#196490) next »