Bug #70667 [Opn->Asn]: strtr() causes invalid writes and a crashes

From: Date: Thu, 08 Oct 2015 11:05:31 +0000
Subject: Bug #70667 [Opn->Asn]: strtr() causes invalid writes and a crashes
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-196491@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=70667&edit=1 ID: 70667 Updated by: tony2001@php.net Reported by: tony2001@php.net Summary: strtr() causes invalid writes and a crashes -Status: Open +Status: Assigned Type: Bug Package: Strings related PHP Version: 7.0Git-2015-10-08 (Git) -Assigned To: +Assigned To: dmitry Block user comment: N Private report: N Previous Comments: ------------------------------------------------------------------------ [2015-10-08 11:05:12] tony2001@php.net Description: ------------ The test example causes invalid writes and a crash in php_strtr_array(). It seems that the problem is in num_bitset allocation, it's too small to store all the bits, which results in a buffer overflow. Test script: --------------- $a = array("{{language_id}}"=>"255", "{{partner_name}}"=>"test1"); var_dump(strtr("Sign in to test1", $a)); Expected result: ---------------- . Actual result: -------------- ==9676== Invalid read of size 8 ==9676== at 0x5A4212: php_strtr_array (string.c:3029) ==9676== by 0x5A5EE7: zif_strtr (string.c:3493) ==9676== by 0x6CDD62: ZEND_DO_ICALL_SPEC_HANDLER (zend_vm_execute.h:583) ==9676== by 0x6CD84C: execute_ex (zend_vm_execute.h:414) ==9676== by 0x6CD92E: zend_execute (zend_vm_execute.h:458) ==9676== by 0x671EFA: zend_execute_scripts (zend.c:1558) ==9676== by 0x5E68CF: php_execute_script (main.c:2525) ==9676== by 0x72EFD4: do_cli (php_cli.c:974) ==9676== by 0x72FE56: main (php_cli.c:1345) ==9676== Address 0x67a1730 is 0 bytes after a block of size 16 alloc'd ==9676== at 0x4C29110: malloc (in /usr/lib64/valgrind/vgpreload_memcheck-amd64-linux.so) ==9676== by 0x63EF22: _emalloc (zend_alloc.c:2410) ==9676== by 0x63F298: _safe_emalloc (zend_alloc.c:2482) ==9676== by 0x63F3BB: _ecalloc (zend_alloc.c:2505) ==9676== by 0x5A40E3: php_strtr_array (string.c:3007) ==9676== by 0x5A5EE7: zif_strtr (string.c:3493) ==9676== by 0x6CDD62: ZEND_DO_ICALL_SPEC_HANDLER (zend_vm_execute.h:583) ==9676== by 0x6CD84C: execute_ex (zend_vm_execute.h:414) ==9676== by 0x6CD92E: zend_execute (zend_vm_execute.h:458) ==9676== by 0x671EFA: zend_execute_scripts (zend.c:1558) ==9676== by 0x5E68CF: php_execute_script (main.c:2525) ==9676== by 0x72EFD4: do_cli (php_cli.c:974) ==9676== by 0x72FE56: main (php_cli.c:1345) ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=70667&edit=1

« previous php.bugs (#196491) next »