Bug #71197 [Asn->Csd]: 2 more segfaults in PHP's range() function

From: Date: Tue, 12 Jan 2016 07:35:46 +0000
Subject: Bug #71197 [Asn->Csd]: 2 more segfaults in PHP's range() function
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-198597@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=71197&edit=1

 ID:                 71197
 Updated by:         ab@php.net
 Reported by:        tpunt@php.net
 Summary:            2 more segfaults in PHP's range() function
-Status:             Assigned
+Status:             Closed
 Type:               Bug
 Package:            Reproducible crash
 Operating System:   Mac OS X Yosemite
 PHP Version:        7.0.1
 Assigned To:        tpunt
 Block user comment: N
 Private report:     N

 New Comment:

Automatic comment on behalf of ab
Revision: http://git.php.net/?p=php-src.git;a=commit;h=391b73b48431aa016e396dc9ad9742e9b1f71cbf
Log: update NEWS for fixed bug #71132, fixed bug #71197


Previous Comments:
------------------------------------------------------------------------
[2015-12-22 16:39:00] tpunt@php.net

PR: https://github.com/php/php-src/pull/1690

------------------------------------------------------------------------
[2015-12-22 15:58:07] tpunt@php.net

Description:
------------
The segfaults are caused by precision loss of large longs being converted to doubles when the
step parameter is a double. The for loops continue infinitely since the
step being added/subtracted upon each iteration is too small to be represented
accurately as a double.

The attached patch adds another condition to each of the for loops by ensuring that the number of
iterations in the loop are less than the size of the range (__calc_size). This prevents
both loops from continuing until segfaulting, however doesn't give an accurate result (due to
__calc_size being incorrect because of aforementioned precision loss).

Test script:
---------------
var_dump(count(range(PHP_INT_MIN, PHP_INT_MIN + 513, .01)));
var_dump(count(range(PHP_INT_MIN + 513, PHP_INT_MIN, .01)));

Expected result:
----------------
// A completely correct output would be:
int(51400)
int(51400)

Actual result:
--------------
Segmentation fault: 11
Segmentation fault: 11


------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=71197&edit=1


Thread (3 messages)

« previous php.bugs (#198597) next »