Bug #71201 [Com]: round() segfault on 64-bit builds

From: Date: Thu, 11 Feb 2016 16:54:08 +0000
Subject: Bug #71201 [Com]: round() segfault on 64-bit builds
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-199167@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=71201&edit=1

 ID:                 71201
 Comment by:         hui at pizda dot eba
 Reported by:        andrew at jmpesp dot org
 Summary:            round() segfault on 64-bit builds
 Status:             Closed
 Type:               Bug
 Package:            Scripting Engine problem
 Operating System:   Linux
 PHP Version:        Irrelevant
 Assigned To:        ab
 Block user comment: N
 Private report:     N

 New Comment:

php хуйня ебаная


Previous Comments:
------------------------------------------------------------------------
[2015-12-23 17:35:59] ab@php.net

Fixed in 0d822f6df946764f3f0348b82efae2e1eaa83aa0. Ttahnks.

------------------------------------------------------------------------
[2015-12-23 16:50:46] ab@php.net

Ups, i meant abs(), not pow() is the issue.

Thanks.

------------------------------------------------------------------------
[2015-12-23 16:49:33] jpauli@php.net

Opening to public, this is not security related

------------------------------------------------------------------------
[2015-12-23 16:44:11] ab@php.net

The Linux pow() function seems to be sensitive to the overflowed values. Please check the patch
below (against 7.0)

diff --git a/ext/standard/math.c b/ext/standard/math.c
index 6059f3d..e79817e 100644
--- a/ext/standard/math.c
+++ b/ext/standard/math.c
@@ -390,7 +390,11 @@ PHP_FUNCTION(round)
        }

        if (ZEND_NUM_ARGS() >= 2) {
-               places = (int) precision;
+               if (precision >= 0) {
+                       places = precision > INT_MAX ? INT_MAX : (int)precision;
+               } else {
+                       places = precision <= INT_MIN ? INT_MIN+1 : (int)precision;
+               }
        }
        convert_scalar_to_number_ex(value);

Thanks

------------------------------------------------------------------------
[2015-12-23 16:29:27] ab@php.net

Thanks for the report. Bug confirmed. But i don't think it is a security issue.

Thanks.

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=71201


--
Edit this bug report at https://bugs.php.net/bug.php?id=71201&edit=1


Thread (1 message)

  • hui at pizda dot eba
  • Unknown Message
    • hui at pizda dot eba
« previous php.bugs (#199167) next »