Bug #62523 [NoF->Opn]: php crashes with segfault when exif_read_data called
| From: | requinix@php.net | Date: | Sun, 31 Jul 2016 10:00:22 +0000 |
| Subject: | Bug #62523 [NoF->Opn]: php crashes with segfault when exif_read_data called | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-202754@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=62523&edit=1
ID: 62523
Updated by: requinix@php.net
Reported by: bigbug at mafia dot lv
Summary: php crashes with segfault when exif_read_data called
-Status: No Feedback
+Status: Open
Type: Bug
Package: Reproducible crash
Operating System: linux
PHP Version: 5.6.23
Assigned To: derick
Block user comment: N
Private report: N
Previous Comments:
------------------------------------------------------------------------
[2016-07-31 04:22:24] php-bugs at lists dot php dot net
No feedback was provided. The bug is being suspended because
we assume that you are no longer experiencing the problem.
If this is not the case and you are able to provide the
information that was requested earlier, please do so and
change the status of the bug back to "Re-Opened". Thank you.
------------------------------------------------------------------------
[2016-07-18 14:17:44] dessander at gmail dot com
$ uname -a
Linux grevus 4.6.4-1-ARCH #1 SMP PREEMPT Mon Jul 11 19:12:32 CEST 2016 x86_64 GNU/Linux
$ php -v
PHP 7.0.8 (cli) (built: Jun 22 2016 16:45:35) ( NTS )
Copyright (c) 1997-2016 The PHP Group
Zend Engine v3.0.0, Copyright (c) 1998-2016 Zend Technologies
$ cat test.php && echo "" && php test.php
<?php
exif_read_data('http://dl.dropbox.com/u/7562584/Bugs/Php/bad_exif.jpeg');
Segmentation fault (core dumped)
------------------------------------------------------------------------
[2016-07-18 13:50:47] cmb@php.net
I've tested with <http://www.getid3.org/temp/62523.jpg>, and that
segfaulted with php-5.5.7-nts-Win32-VC11-x86 and earlier, but not
as of php-5.5.8-nts-Win32-VC11-x86. That lead me to a commit which
added tests for this bug[1]. This commit shortly follows the
merge of PR #293[2], where it is claimed that the PR is unrelated
to this bug. :?
<http://dl.dropbox.com/u/7562584/Bugs/Php/bad_exif.jpeg>
however,
has been reported to segfault with 5.6.15, but I can't reproduce
that (neither on Windows nor on Linux); instead I get the warning
"Unable to open file" (which doesn't happen for the other image).
So perhaps we're dealing with two bugs here.
[1] <https://github.com/php/php-src/commit/2fa5f39>
------------------------------------------------------------------------
[2016-07-17 23:21:36] stas@php.net
Derick, is this still an issue? If so, could yu please provide the faulty image?
------------------------------------------------------------------------
[2015-11-26 10:45:38] derick@php.net
I can very much reproduce this too with 5.6.
It looks like "encoding_to=0x0" in frame 2 is the problem.
Backtrace:
158 if (mbfl_convert_filter_get_vtbl(convd->from->no_encoding, convd->to->no_encoding)
!= NULL) {
(gdb) bt full
#0 0x000000000074bdd9 in mbfl_buffer_converter_new2 (from=0x1387300 <mbfl_encoding_jis>,
to=0x0, buf_initsz=38)
at /home/derick/dev/php/php-src.git/ext/mbstring/libmbfl/mbfl/mbfilter.c:158
convd = 0x7fffe948cfa0
#1 0x0000000000754ca0 in php_mb_zend_encoding_converter (to=0x7fffffffc668,
to_length=0x7fffffffc038, from=0x7fffe948f32e "", from_length=38, encoding_to=0x0,
encoding_from=0x1387300 <mbfl_encoding_jis>) at
/home/derick/dev/php/php-src.git/ext/mbstring/mbstring.c:945
string = {no_language = mbfl_no_language_neutral, no_encoding = mbfl_no_encoding_jis, val =
0x7fffe948f32e "", len = 38}
result = {no_language = mbfl_no_language_uni, no_encoding = mbfl_no_encoding_pass, val =
0x0, len = 0}
convd = 0x5800000001
status = 0
loc = 0
#2 0x0000000000ab6e3f in zend_multibyte_encoding_converter (to=0x7fffffffc668,
to_length=0x7fffffffc038, from=0x7fffe948f32e "", from_length=38, encoding_to=0x0,
encoding_from=0x1387300 <mbfl_encoding_jis>) at
/home/derick/dev/php/php-src.git/Zend/zend_multibyte.c:150
No locals.
#3 0x0000000000635c9b in exif_process_user_comment (ImageInfo=0x7fffffffc5f0,
pszInfoPtr=0x7fffffffc668, pszEncoding=0x7fffffffc678, szValuePtr=0x7fffe948f32e "",
ByteCount=38) at /home/derick/dev/php/php-src.git/ext/exif/exif.c:2658
a = 0
decode = 0x7fffffffc060 "\200\301\377\377\377\177"
len = 140737107259986
#4 0x0000000000636c54 in exif_process_IFD_TAG (ImageInfo=0x7fffffffc5f0, dir_entry=0x7fffe948f24a
"\206\222\a", offset_base=0x7fffe948f090 "II*", IFDlength=24564,
displacement=12, section_index=7, ReadNextIFD=1, tag_table=0x13777a0 <tag_table_IFD>) at
/home/derick/dev/php/php-src.git/ext/exif/exif.c:2969
length = 140737107285952
tag = 37510
format = 7
components = 46
value_ptr = 0x7fffe948f326 "JIS"
tagname = "FocalLength\000\000ce\000\000\000ixel\000\000$\371\245\000\000\000\000\000
\301\377\377\377\177\000\000N\370\245", '\000' <repeats 13 times>,
"Ps\305\000\000\000\000"
cbuf = "\320\300\377\377\377\177\000\000\230\363\245", '\000'
<repeats 17 times>, "\232\006\000"
outside = 0x0
byte_count = 46
offset_val = 662
fpos = 6502854
fgot = 140737488339328
byte_count_signed = 46
tmp_xp = 0x7fffe948f16c
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=62523
--
Edit this bug report at https://bugs.php.net/bug.php?id=62523&edit=1