Bug #62523 [NoF->Fbk]: php crashes with segfault when exif_read_data called

From: Date: Sun, 17 Jul 2016 23:21:39 +0000
Subject: Bug #62523 [NoF->Fbk]: php crashes with segfault when exif_read_data called
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-202384@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=62523&edit=1 ID: 62523 Updated by: stas@php.net Reported by: bigbug at mafia dot lv Summary: php crashes with segfault when exif_read_data called -Status: No Feedback +Status: Feedback Type: Bug Package: Reproducible crash Operating System: linux -PHP Version: 5.3Git-2012-07-10 (snap) +PHP Version: 5.6.23 -Assigned To: rasmus +Assigned To: derick Block user comment: N Private report: N New Comment: Derick, is this still an issue? If so, could yu please provide the faulty image? Previous Comments: ------------------------------------------------------------------------ [2015-11-26 10:45:38] derick@php.net I can very much reproduce this too with 5.6. It looks like "encoding_to=0x0" in frame 2 is the problem. Backtrace: 158 if (mbfl_convert_filter_get_vtbl(convd->from->no_encoding, convd->to->no_encoding) != NULL) { (gdb) bt full #0 0x000000000074bdd9 in mbfl_buffer_converter_new2 (from=0x1387300 <mbfl_encoding_jis>, to=0x0, buf_initsz=38) at /home/derick/dev/php/php-src.git/ext/mbstring/libmbfl/mbfl/mbfilter.c:158 convd = 0x7fffe948cfa0 #1 0x0000000000754ca0 in php_mb_zend_encoding_converter (to=0x7fffffffc668, to_length=0x7fffffffc038, from=0x7fffe948f32e "", from_length=38, encoding_to=0x0, encoding_from=0x1387300 <mbfl_encoding_jis>) at /home/derick/dev/php/php-src.git/ext/mbstring/mbstring.c:945 string = {no_language = mbfl_no_language_neutral, no_encoding = mbfl_no_encoding_jis, val = 0x7fffe948f32e "", len = 38} result = {no_language = mbfl_no_language_uni, no_encoding = mbfl_no_encoding_pass, val = 0x0, len = 0} convd = 0x5800000001 status = 0 loc = 0 #2 0x0000000000ab6e3f in zend_multibyte_encoding_converter (to=0x7fffffffc668, to_length=0x7fffffffc038, from=0x7fffe948f32e "", from_length=38, encoding_to=0x0, encoding_from=0x1387300 <mbfl_encoding_jis>) at /home/derick/dev/php/php-src.git/Zend/zend_multibyte.c:150 No locals. #3 0x0000000000635c9b in exif_process_user_comment (ImageInfo=0x7fffffffc5f0, pszInfoPtr=0x7fffffffc668, pszEncoding=0x7fffffffc678, szValuePtr=0x7fffe948f32e "", ByteCount=38) at /home/derick/dev/php/php-src.git/ext/exif/exif.c:2658 a = 0 decode = 0x7fffffffc060 "\200\301\377\377\377\177" len = 140737107259986 #4 0x0000000000636c54 in exif_process_IFD_TAG (ImageInfo=0x7fffffffc5f0, dir_entry=0x7fffe948f24a "\206\222\a", offset_base=0x7fffe948f090 "II*", IFDlength=24564, displacement=12, section_index=7, ReadNextIFD=1, tag_table=0x13777a0 <tag_table_IFD>) at /home/derick/dev/php/php-src.git/ext/exif/exif.c:2969 length = 140737107285952 tag = 37510 format = 7 components = 46 value_ptr = 0x7fffe948f326 "JIS" tagname = "FocalLength\000\000ce\000\000\000ixel\000\000$\371\245\000\000\000\000\000 \301\377\377\377\177\000\000N\370\245", '\000' <repeats 13 times>, "Ps\305\000\000\000\000" cbuf = "\320\300\377\377\377\177\000\000\230\363\245", '\000' <repeats 17 times>, "\232\006\000" outside = 0x0 byte_count = 46 offset_val = 662 fpos = 6502854 fgot = 140737488339328 byte_count_signed = 46 tmp_xp = 0x7fffe948f16c ------------------------------------------------------------------------ [2015-11-26 08:25:03] dessander at gmail dot com $ uname -a Linux grevus 4.2.5-1-ARCH #1 SMP PREEMPT Tue Oct 27 08:13:28 CET 2015 x86_64 GNU/Linux $ php -v PHP 5.6.15 (cli) (built: Nov 10 2015 20:22:58) Copyright (c) 1997-2015 The PHP Group Zend Engine v2.6.0, Copyright (c) 1998-2015 Zend Technologies $ cat test.php && echo "" && php test.php <?php exif_read_data('http://dl.dropbox.com/u/7562584/Bugs/Php/bad_exif.jpeg'); Segmentation fault (core dumped) ===================== Still exists ------------------------------------------------------------------------ [2015-11-26 08:11:48] eugene dot reich at gmail dot com Bug exists at this moment on lastest version. ------------------------------------------------------------------------ [2015-11-25 19:44:24] rgallico at gmail dot com I'm using PHP Version 5.6.14-0+deb8u1 on virtual machine VMware with Debian 8.0 and Debian 8.2 ------------------------------------------------------------------------ [2015-02-22 04:22:15] php-bugs at lists dot php dot net No feedback was provided. The bug is being suspended because we assume that you are no longer experiencing the problem. If this is not the case and you are able to provide the information that was requested earlier, please do so and change the status of the bug back to "Re-Opened". Thank you. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=62523 -- Edit this bug report at https://bugs.php.net/bug.php?id=62523&edit=1

« previous php.bugs (#202384) next »