Bug #62523 [NoF->Opn]: php crashes with segfault when exif_read_data called

From: Date: Sun, 31 Jul 2016 10:00:22 +0000
Subject: Bug #62523 [NoF->Opn]: php crashes with segfault when exif_read_data called
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-202754@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=62523&edit=1 ID: 62523 Updated by: requinix@php.net Reported by: bigbug at mafia dot lv Summary: php crashes with segfault when exif_read_data called -Status: No Feedback +Status: Open Type: Bug Package: Reproducible crash Operating System: linux PHP Version: 5.6.23 Assigned To: derick Block user comment: N Private report: N Previous Comments: ------------------------------------------------------------------------ [2016-07-31 04:22:24] php-bugs at lists dot php dot net No feedback was provided. The bug is being suspended because we assume that you are no longer experiencing the problem. If this is not the case and you are able to provide the information that was requested earlier, please do so and change the status of the bug back to "Re-Opened". Thank you. ------------------------------------------------------------------------ [2016-07-18 14:17:44] dessander at gmail dot com $ uname -a Linux grevus 4.6.4-1-ARCH #1 SMP PREEMPT Mon Jul 11 19:12:32 CEST 2016 x86_64 GNU/Linux $ php -v PHP 7.0.8 (cli) (built: Jun 22 2016 16:45:35) ( NTS ) Copyright (c) 1997-2016 The PHP Group Zend Engine v3.0.0, Copyright (c) 1998-2016 Zend Technologies $ cat test.php && echo "" && php test.php <?php exif_read_data('http://dl.dropbox.com/u/7562584/Bugs/Php/bad_exif.jpeg'); Segmentation fault (core dumped) ------------------------------------------------------------------------ [2016-07-18 13:50:47] cmb@php.net I've tested with <http://www.getid3.org/temp/62523.jpg>, and that segfaulted with php-5.5.7-nts-Win32-VC11-x86 and earlier, but not as of php-5.5.8-nts-Win32-VC11-x86. That lead me to a commit which added tests for this bug[1]. This commit shortly follows the merge of PR #293[2], where it is claimed that the PR is unrelated to this bug. :? <http://dl.dropbox.com/u/7562584/Bugs/Php/bad_exif.jpeg> however, has been reported to segfault with 5.6.15, but I can't reproduce that (neither on Windows nor on Linux); instead I get the warning "Unable to open file" (which doesn't happen for the other image). So perhaps we're dealing with two bugs here. [1] <https://github.com/php/php-src/commit/2fa5f39> ------------------------------------------------------------------------ [2016-07-17 23:21:36] stas@php.net Derick, is this still an issue? If so, could yu please provide the faulty image? ------------------------------------------------------------------------ [2015-11-26 10:45:38] derick@php.net I can very much reproduce this too with 5.6. It looks like "encoding_to=0x0" in frame 2 is the problem. Backtrace: 158 if (mbfl_convert_filter_get_vtbl(convd->from->no_encoding, convd->to->no_encoding) != NULL) { (gdb) bt full #0 0x000000000074bdd9 in mbfl_buffer_converter_new2 (from=0x1387300 <mbfl_encoding_jis>, to=0x0, buf_initsz=38) at /home/derick/dev/php/php-src.git/ext/mbstring/libmbfl/mbfl/mbfilter.c:158 convd = 0x7fffe948cfa0 #1 0x0000000000754ca0 in php_mb_zend_encoding_converter (to=0x7fffffffc668, to_length=0x7fffffffc038, from=0x7fffe948f32e "", from_length=38, encoding_to=0x0, encoding_from=0x1387300 <mbfl_encoding_jis>) at /home/derick/dev/php/php-src.git/ext/mbstring/mbstring.c:945 string = {no_language = mbfl_no_language_neutral, no_encoding = mbfl_no_encoding_jis, val = 0x7fffe948f32e "", len = 38} result = {no_language = mbfl_no_language_uni, no_encoding = mbfl_no_encoding_pass, val = 0x0, len = 0} convd = 0x5800000001 status = 0 loc = 0 #2 0x0000000000ab6e3f in zend_multibyte_encoding_converter (to=0x7fffffffc668, to_length=0x7fffffffc038, from=0x7fffe948f32e "", from_length=38, encoding_to=0x0, encoding_from=0x1387300 <mbfl_encoding_jis>) at /home/derick/dev/php/php-src.git/Zend/zend_multibyte.c:150 No locals. #3 0x0000000000635c9b in exif_process_user_comment (ImageInfo=0x7fffffffc5f0, pszInfoPtr=0x7fffffffc668, pszEncoding=0x7fffffffc678, szValuePtr=0x7fffe948f32e "", ByteCount=38) at /home/derick/dev/php/php-src.git/ext/exif/exif.c:2658 a = 0 decode = 0x7fffffffc060 "\200\301\377\377\377\177" len = 140737107259986 #4 0x0000000000636c54 in exif_process_IFD_TAG (ImageInfo=0x7fffffffc5f0, dir_entry=0x7fffe948f24a "\206\222\a", offset_base=0x7fffe948f090 "II*", IFDlength=24564, displacement=12, section_index=7, ReadNextIFD=1, tag_table=0x13777a0 <tag_table_IFD>) at /home/derick/dev/php/php-src.git/ext/exif/exif.c:2969 length = 140737107285952 tag = 37510 format = 7 components = 46 value_ptr = 0x7fffe948f326 "JIS" tagname = "FocalLength\000\000ce\000\000\000ixel\000\000$\371\245\000\000\000\000\000 \301\377\377\377\177\000\000N\370\245", '\000' <repeats 13 times>, "Ps\305\000\000\000\000" cbuf = "\320\300\377\377\377\177\000\000\230\363\245", '\000' <repeats 17 times>, "\232\006\000" outside = 0x0 byte_count = 46 offset_val = 662 fpos = 6502854 fgot = 140737488339328 byte_count_signed = 46 tmp_xp = 0x7fffe948f16c ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=62523 -- Edit this bug report at https://bugs.php.net/bug.php?id=62523&edit=1

« previous php.bugs (#202754) next »