Edit report at https://bugs.php.net/bug.php?id=71201&edit=1
ID: 71201
Comment by: hui at pizda dot eba
Reported by: andrew at jmpesp dot org
Summary: round() segfault on 64-bit builds
Status: Closed
Type: Bug
Package: Scripting Engine problem
Operating System: Linux
PHP Version: Irrelevant
Assigned To: ab
Block user comment: N
Private report: N
New Comment:
php Ñ ÑÐ¹Ð½Ñ ÐµÐ±Ð°Ð½Ð°Ñ
Previous Comments:
------------------------------------------------------------------------
[2015-12-23 17:35:59] ab@php.net
Fixed in 0d822f6df946764f3f0348b82efae2e1eaa83aa0. Ttahnks.
------------------------------------------------------------------------
[2015-12-23 16:50:46] ab@php.net
Ups, i meant abs(), not pow() is the issue.
Thanks.
------------------------------------------------------------------------
[2015-12-23 16:49:33] jpauli@php.net
Opening to public, this is not security related
------------------------------------------------------------------------
[2015-12-23 16:44:11] ab@php.net
The Linux pow() function seems to be sensitive to the overflowed values. Please check the patch
below (against 7.0)
diff --git a/ext/standard/math.c b/ext/standard/math.c
index 6059f3d..e79817e 100644
--- a/ext/standard/math.c
+++ b/ext/standard/math.c
@@ -390,7 +390,11 @@ PHP_FUNCTION(round)
}
if (ZEND_NUM_ARGS() >= 2) {
- places = (int) precision;
+ if (precision >= 0) {
+ places = precision > INT_MAX ? INT_MAX : (int)precision;
+ } else {
+ places = precision <= INT_MIN ? INT_MIN+1 : (int)precision;
+ }
}
convert_scalar_to_number_ex(value);
Thanks
------------------------------------------------------------------------
[2015-12-23 16:29:27] ab@php.net
Thanks for the report. Bug confirmed. But i don't think it is a security issue.
Thanks.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=71201
--
Edit this bug report at https://bugs.php.net/bug.php?id=71201&edit=1