Edit report at https://bugs.php.net/bug.php?id=62523&edit=1
ID: 62523
Comment by: dessander at gmail dot com
Reported by: bigbug at mafia dot lv
Summary: php crashes with segfault when exif_read_data called
Status: Feedback
Type: Bug
Package: Reproducible crash
Operating System: linux
PHP Version: 5.6.23
Assigned To: derick
Block user comment: N
Private report: N
New Comment:
$ uname -a
Linux grevus 4.6.4-1-ARCH #1 SMP PREEMPT Mon Jul 11 19:12:32 CEST 2016 x86_64 GNU/Linux
$ php -v
PHP 7.0.8 (cli) (built: Jun 22 2016 16:45:35) ( NTS )
Copyright (c) 1997-2016 The PHP Group
Zend Engine v3.0.0, Copyright (c) 1998-2016 Zend Technologies
$ cat test.php && echo "" && php test.php
<?php
exif_read_data('http://dl.dropbox.com/u/7562584/Bugs/Php/bad_exif.jpeg');
Segmentation fault (core dumped)
Previous Comments:
------------------------------------------------------------------------
[2016-07-18 13:50:47] cmb@php.net
I've tested with <http://www.getid3.org/temp/62523.jpg>, and that
segfaulted with php-5.5.7-nts-Win32-VC11-x86 and earlier, but not
as of php-5.5.8-nts-Win32-VC11-x86. That lead me to a commit which
added tests for this bug[1]. This commit shortly follows the
merge of PR #293[2], where it is claimed that the PR is unrelated
to this bug. :?
<http://dl.dropbox.com/u/7562584/Bugs/Php/bad_exif.jpeg>
however,
has been reported to segfault with 5.6.15, but I can't reproduce
that (neither on Windows nor on Linux); instead I get the warning
"Unable to open file" (which doesn't happen for the other image).
So perhaps we're dealing with two bugs here.
[1] <https://github.com/php/php-src/commit/2fa5f39>
------------------------------------------------------------------------
[2016-07-17 23:21:36] stas@php.net
Derick, is this still an issue? If so, could yu please provide the faulty image?
------------------------------------------------------------------------
[2015-11-26 10:45:38] derick@php.net
I can very much reproduce this too with 5.6.
It looks like "encoding_to=0x0" in frame 2 is the problem.
Backtrace:
158 if (mbfl_convert_filter_get_vtbl(convd->from->no_encoding, convd->to->no_encoding)
!= NULL) {
(gdb) bt full
#0 0x000000000074bdd9 in mbfl_buffer_converter_new2 (from=0x1387300 <mbfl_encoding_jis>,
to=0x0, buf_initsz=38)
at /home/derick/dev/php/php-src.git/ext/mbstring/libmbfl/mbfl/mbfilter.c:158
convd = 0x7fffe948cfa0
#1 0x0000000000754ca0 in php_mb_zend_encoding_converter (to=0x7fffffffc668,
to_length=0x7fffffffc038, from=0x7fffe948f32e "", from_length=38, encoding_to=0x0,
encoding_from=0x1387300 <mbfl_encoding_jis>) at
/home/derick/dev/php/php-src.git/ext/mbstring/mbstring.c:945
string = {no_language = mbfl_no_language_neutral, no_encoding = mbfl_no_encoding_jis, val =
0x7fffe948f32e "", len = 38}
result = {no_language = mbfl_no_language_uni, no_encoding = mbfl_no_encoding_pass, val =
0x0, len = 0}
convd = 0x5800000001
status = 0
loc = 0
#2 0x0000000000ab6e3f in zend_multibyte_encoding_converter (to=0x7fffffffc668,
to_length=0x7fffffffc038, from=0x7fffe948f32e "", from_length=38, encoding_to=0x0,
encoding_from=0x1387300 <mbfl_encoding_jis>) at
/home/derick/dev/php/php-src.git/Zend/zend_multibyte.c:150
No locals.
#3 0x0000000000635c9b in exif_process_user_comment (ImageInfo=0x7fffffffc5f0,
pszInfoPtr=0x7fffffffc668, pszEncoding=0x7fffffffc678, szValuePtr=0x7fffe948f32e "",
ByteCount=38) at /home/derick/dev/php/php-src.git/ext/exif/exif.c:2658
a = 0
decode = 0x7fffffffc060 "\200\301\377\377\377\177"
len = 140737107259986
#4 0x0000000000636c54 in exif_process_IFD_TAG (ImageInfo=0x7fffffffc5f0, dir_entry=0x7fffe948f24a
"\206\222\a", offset_base=0x7fffe948f090 "II*", IFDlength=24564,
displacement=12, section_index=7, ReadNextIFD=1, tag_table=0x13777a0 <tag_table_IFD>) at
/home/derick/dev/php/php-src.git/ext/exif/exif.c:2969
length = 140737107285952
tag = 37510
format = 7
components = 46
value_ptr = 0x7fffe948f326 "JIS"
tagname = "FocalLength\000\000ce\000\000\000ixel\000\000$\371\245\000\000\000\000\000
\301\377\377\377\177\000\000N\370\245", '\000' <repeats 13 times>,
"Ps\305\000\000\000\000"
cbuf = "\320\300\377\377\377\177\000\000\230\363\245", '\000'
<repeats 17 times>, "\232\006\000"
outside = 0x0
byte_count = 46
offset_val = 662
fpos = 6502854
fgot = 140737488339328
byte_count_signed = 46
tmp_xp = 0x7fffe948f16c
------------------------------------------------------------------------
[2015-11-26 08:25:03] dessander at gmail dot com
$ uname -a
Linux grevus 4.2.5-1-ARCH #1 SMP PREEMPT Tue Oct 27 08:13:28 CET 2015 x86_64 GNU/Linux
$ php -v
PHP 5.6.15 (cli) (built: Nov 10 2015 20:22:58)
Copyright (c) 1997-2015 The PHP Group
Zend Engine v2.6.0, Copyright (c) 1998-2015 Zend Technologies
$ cat test.php && echo "" && php test.php
<?php
exif_read_data('http://dl.dropbox.com/u/7562584/Bugs/Php/bad_exif.jpeg');
Segmentation fault (core dumped)
=====================
Still exists
------------------------------------------------------------------------
[2015-11-26 08:11:48] eugene dot reich at gmail dot com
Bug exists at this moment on lastest version.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=62523
--
Edit this bug report at https://bugs.php.net/bug.php?id=62523&edit=1