Bug #71001 [Opn]: Regex with long input string causes SIGSEGV
| From: | norman at cure53 dot de | Date: | Mon, 30 Nov 2015 15:51:39 +0000 |
| Subject: | Bug #71001 [Opn]: Regex with long input string causes SIGSEGV | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-197523@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=71001&edit=1
ID: 71001
User updated by: norman at cure53 dot de
Reported by: norman at cure53 dot de
Summary: Regex with long input string causes SIGSEGV
Status: Open
Type: Bug
Package: PCRE related
Operating System: Centos 6
PHP Version: 5.6.16
Block user comment: N
Private report: N
New Comment:
Changed type to security
Previous Comments:
------------------------------------------------------------------------
[2015-11-30 15:50:29] norman at cure53 dot de
Description:
------------
The following regex combined with an overly long string causes a sigsegv in PHP 5.3.20 - 5.6.16.
No special modules or php.ini directives have been used.
Test script:
---------------
<?php
// 5.3.20 - 5.6.16
$regex = "/^([a-z0-9]([a-z0-9-]*[a-z0-9])?\.)*[a-z]([a-z0-9-]*[a-z0-9])?\.?$/i";
$count = 10000;
$string = str_repeat("a.",$count)."x.com";
if (preg_match($regex, $string)) {
print "not vulnerable";
}
?>
Expected result:
----------------
The script should print "not vulnerable" or exit normally.
Actual result:
--------------
The PHP process terminates with a sigsegv: php-fpm[31329]: [WARNING] [pool www] child 25489 exited
on signal 11 (SIGSEGV)
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=71001&edit=1