Bug #62523 [Asn]: php crashes with segfault when exif_read_data called

From: Date: Mon, 01 Aug 2016 08:41:33 +0000
Subject: Bug #62523 [Asn]: php crashes with segfault when exif_read_data called
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-202794@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=62523&edit=1

 ID:                 62523
 User updated by:    romans dot heimanis at gmail dot com
 Reported by:        romans dot heimanis at gmail dot com
 Summary:            php crashes with segfault when exif_read_data called
 Status:             Assigned
 Type:               Bug
 Package:            Reproducible crash
 Operating System:   linux
 PHP Version:        5.6.23
 Assigned To:        stas
 Block user comment: N
 Private report:     N

 New Comment:

Just changing original e-mail


Previous Comments:
------------------------------------------------------------------------
[2016-08-01 06:18:52] stas@php.net

Sorry, unable to reproduce any issues on either 5.6 or 7.0 with either bad_exif.jpeg or  62523.jpg.
No segfaults, not complaints, nothing.

------------------------------------------------------------------------
[2016-08-01 02:56:51] stas@php.net

I'm not sure what this has to do with openssl (given that the URL is not HTTPS). But I'll
check what happens with these images.

------------------------------------------------------------------------
[2016-07-31 11:56:30] cmb@php.net

<?php
exif_read_data('http://dl.dropbox.com/u/7562584/Bugs/Php/bad_exif.jpeg');

Indeed, valgrind reports

| Conditional jump or move depends on uninitialised value(s)

In this case cert_captured is uninitialized in the check whether
peer_cert has to be freed[1]. After adding a proper initializer,
there are still memory leaks reported by valgrind (also when
file_get_contents() is used instead of exif_read_data() with the
unmodified C code).

Stas, could you have a look at this issue?

[1] <https://github.com/php/php-src/blob/PHP-7.0.9/ext/openssl/xp_ssl.c#L1893>

------------------------------------------------------------------------
[2016-07-31 04:22:24] php-bugs at lists dot php dot net

No feedback was provided. The bug is being suspended because
we assume that you are no longer experiencing the problem.
If this is not the case and you are able to provide the
information that was requested earlier, please do so and
change the status of the bug back to "Re-Opened". Thank you.

------------------------------------------------------------------------
[2016-07-18 14:17:44] dessander at gmail dot com

$ uname -a
Linux grevus 4.6.4-1-ARCH #1 SMP PREEMPT Mon Jul 11 19:12:32 CEST 2016 x86_64 GNU/Linux
$ php -v
PHP 7.0.8 (cli) (built: Jun 22 2016 16:45:35) ( NTS )
Copyright (c) 1997-2016 The PHP Group
Zend Engine v3.0.0, Copyright (c) 1998-2016 Zend Technologies
$ cat test.php && echo "" && php test.php
<?php

exif_read_data('http://dl.dropbox.com/u/7562584/Bugs/Php/bad_exif.jpeg');

Segmentation fault (core dumped)

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=62523


--
Edit this bug report at https://bugs.php.net/bug.php?id=62523&edit=1


Thread (41 messages)

« previous php.bugs (#202794) next »