Bug #62523 [Com]: php crashes with segfault when exif_read_data called

From: Date: Mon, 18 Jul 2016 14:17:48 +0000
Subject: Bug #62523 [Com]: php crashes with segfault when exif_read_data called
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-202399@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=62523&edit=1

 ID:                 62523
 Comment by:         dessander at gmail dot com
 Reported by:        bigbug at mafia dot lv
 Summary:            php crashes with segfault when exif_read_data called
 Status:             Feedback
 Type:               Bug
 Package:            Reproducible crash
 Operating System:   linux
 PHP Version:        5.6.23
 Assigned To:        derick
 Block user comment: N
 Private report:     N

 New Comment:

$ uname -a
Linux grevus 4.6.4-1-ARCH #1 SMP PREEMPT Mon Jul 11 19:12:32 CEST 2016 x86_64 GNU/Linux
$ php -v
PHP 7.0.8 (cli) (built: Jun 22 2016 16:45:35) ( NTS )
Copyright (c) 1997-2016 The PHP Group
Zend Engine v3.0.0, Copyright (c) 1998-2016 Zend Technologies
$ cat test.php && echo "" && php test.php
<?php

exif_read_data('http://dl.dropbox.com/u/7562584/Bugs/Php/bad_exif.jpeg');

Segmentation fault (core dumped)


Previous Comments:
------------------------------------------------------------------------
[2016-07-18 13:50:47] cmb@php.net

I've tested with <http://www.getid3.org/temp/62523.jpg>, and that
segfaulted with php-5.5.7-nts-Win32-VC11-x86 and earlier, but not
as of php-5.5.8-nts-Win32-VC11-x86. That lead me to a commit which
added tests for this bug[1]. This commit shortly follows the
merge of PR #293[2], where it is claimed that the PR is unrelated
to this bug. :?

<http://dl.dropbox.com/u/7562584/Bugs/Php/bad_exif.jpeg>
however,
has been reported to segfault with 5.6.15, but I can't reproduce
that (neither on Windows nor on Linux); instead I get the warning
"Unable to open file" (which doesn't happen for the other image).

So perhaps we're dealing with two bugs here.

[1] <https://github.com/php/php-src/commit/2fa5f39>

------------------------------------------------------------------------
[2016-07-17 23:21:36] stas@php.net

Derick, is this still an issue? If so, could yu please provide the faulty image?

------------------------------------------------------------------------
[2015-11-26 10:45:38] derick@php.net

I can very much reproduce this too with 5.6.

It looks like "encoding_to=0x0" in frame 2 is the problem.

Backtrace:

158		if (mbfl_convert_filter_get_vtbl(convd->from->no_encoding, convd->to->no_encoding)
!= NULL) {
(gdb) bt full
#0  0x000000000074bdd9 in mbfl_buffer_converter_new2 (from=0x1387300 <mbfl_encoding_jis>,
to=0x0, buf_initsz=38)
    at /home/derick/dev/php/php-src.git/ext/mbstring/libmbfl/mbfl/mbfilter.c:158
        convd = 0x7fffe948cfa0
#1  0x0000000000754ca0 in php_mb_zend_encoding_converter (to=0x7fffffffc668,
to_length=0x7fffffffc038, from=0x7fffe948f32e "", from_length=38, encoding_to=0x0, 
    encoding_from=0x1387300 <mbfl_encoding_jis>) at
/home/derick/dev/php/php-src.git/ext/mbstring/mbstring.c:945
        string = {no_language = mbfl_no_language_neutral, no_encoding = mbfl_no_encoding_jis, val =
0x7fffe948f32e "", len = 38}
        result = {no_language = mbfl_no_language_uni, no_encoding = mbfl_no_encoding_pass, val =
0x0, len = 0}
        convd = 0x5800000001
        status = 0
        loc = 0
#2  0x0000000000ab6e3f in zend_multibyte_encoding_converter (to=0x7fffffffc668,
to_length=0x7fffffffc038, from=0x7fffe948f32e "", from_length=38, encoding_to=0x0, 
    encoding_from=0x1387300 <mbfl_encoding_jis>) at
/home/derick/dev/php/php-src.git/Zend/zend_multibyte.c:150
No locals.
#3  0x0000000000635c9b in exif_process_user_comment (ImageInfo=0x7fffffffc5f0,
pszInfoPtr=0x7fffffffc668, pszEncoding=0x7fffffffc678, szValuePtr=0x7fffe948f32e "", 
    ByteCount=38) at /home/derick/dev/php/php-src.git/ext/exif/exif.c:2658
        a = 0
        decode = 0x7fffffffc060 "\200\301\377\377\377\177"
        len = 140737107259986
#4  0x0000000000636c54 in exif_process_IFD_TAG (ImageInfo=0x7fffffffc5f0, dir_entry=0x7fffe948f24a
"\206\222\a", offset_base=0x7fffe948f090 "II*", IFDlength=24564, 
    displacement=12, section_index=7, ReadNextIFD=1, tag_table=0x13777a0 <tag_table_IFD>) at
/home/derick/dev/php/php-src.git/ext/exif/exif.c:2969
        length = 140737107285952
        tag = 37510
        format = 7
        components = 46
        value_ptr = 0x7fffe948f326 "JIS"
        tagname = "FocalLength\000\000ce\000\000\000ixel\000\000$\371\245\000\000\000\000\000
\301\377\377\377\177\000\000N\370\245", '\000' <repeats 13 times>,
"Ps\305\000\000\000\000"
        cbuf = "\320\300\377\377\377\177\000\000\230\363\245", '\000'
<repeats 17 times>, "\232\006\000"
        outside = 0x0
        byte_count = 46
        offset_val = 662
        fpos = 6502854
        fgot = 140737488339328
        byte_count_signed = 46
        tmp_xp = 0x7fffe948f16c

------------------------------------------------------------------------
[2015-11-26 08:25:03] dessander at gmail dot com

$ uname -a
Linux grevus 4.2.5-1-ARCH #1 SMP PREEMPT Tue Oct 27 08:13:28 CET 2015 x86_64 GNU/Linux

$ php -v
PHP 5.6.15 (cli) (built: Nov 10 2015 20:22:58) 
Copyright (c) 1997-2015 The PHP Group
Zend Engine v2.6.0, Copyright (c) 1998-2015 Zend Technologies

$ cat test.php && echo "" && php test.php 
<?php
	exif_read_data('http://dl.dropbox.com/u/7562584/Bugs/Php/bad_exif.jpeg');

Segmentation fault (core dumped)

=====================
Still exists

------------------------------------------------------------------------
[2015-11-26 08:11:48] eugene dot reich at gmail dot com

Bug exists at this moment on lastest version.

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=62523


--
Edit this bug report at https://bugs.php.net/bug.php?id=62523&edit=1


Thread (41 messages)

« previous php.bugs (#202399) next »