Bug #71197 [Asn->Csd]: 2 more segfaults in PHP's range() function
Edit report at https://bugs.php.net/bug.php?id=71197&edit=1
ID: 71197
Updated by: ab@php.net
Reported by: tpunt@php.net
Summary: 2 more segfaults in PHP's range() function
-Status: Assigned
+Status: Closed
Type: Bug
Package: Reproducible crash
Operating System: Mac OS X Yosemite
PHP Version: 7.0.1
Assigned To: tpunt
Block user comment: N
Private report: N
New Comment:
Automatic comment on behalf of ab
Revision: http://git.php.net/?p=php-src.git;a=commit;h=391b73b48431aa016e396dc9ad9742e9b1f71cbf
Log: update NEWS for fixed bug #71132, fixed bug #71197
Previous Comments:
------------------------------------------------------------------------
[2015-12-22 16:39:00] tpunt@php.net
PR: https://github.com/php/php-src/pull/1690
------------------------------------------------------------------------
[2015-12-22 15:58:07] tpunt@php.net
Description:
------------
The segfaults are caused by precision loss of large longs being converted to doubles when the
step parameter is a double. The for loops continue infinitely since the
step being added/subtracted upon each iteration is too small to be represented
accurately as a double.
The attached patch adds another condition to each of the for loops by ensuring that the number of
iterations in the loop are less than the size of the range (__calc_size). This prevents
both loops from continuing until segfaulting, however doesn't give an accurate result (due to
__calc_size being incorrect because of aforementioned precision loss).
Test script:
---------------
var_dump(count(range(PHP_INT_MIN, PHP_INT_MIN + 513, .01)));
var_dump(count(range(PHP_INT_MIN + 513, PHP_INT_MIN, .01)));
Expected result:
----------------
// A completely correct output would be:
int(51400)
int(51400)
Actual result:
--------------
Segmentation fault: 11
Segmentation fault: 11
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=71197&edit=1
Thread (3 messages)