Bug #62523 [Asn]: php crashes with segfault when exif_read_data called
| From: | cmb@php.net | Date: | Mon, 01 Aug 2016 09:49:41 +0000 |
| Subject: | Bug #62523 [Asn]: php crashes with segfault when exif_read_data called | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-202796@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=62523&edit=1
ID: 62523
Updated by: cmb@php.net
Reported by: romans dot heimanis at gmail dot com
Summary: php crashes with segfault when exif_read_data called
Status: Assigned
Type: Bug
Package: Reproducible crash
Operating System: linux
PHP Version: 5.6.23
Assigned To: stas
Block user comment: N
Private report: N
New Comment:
> I'm not sure what this has to do with openssl (given that the
> URL is not HTTPS).
$ curl -I -s http://dl.dropbox.com/u/7562584/Bugs/Php/bad_exif.jpeg'
| grep location
location: http://dl.dropboxusercontent.com/u/7562584/Bugs/Php/bad_exif.jpeg
> Sorry, unable to reproduce any issues on either 5.6 or 7.0 with
> either bad_exif.jpeg or 62523.jpg.
Reading the exif data from a local file shows no issues; the
problem is with the connection to the server. I've tested and
debugged with the 5.6 branch, but I assume the issue occurs also
with newer versions (PHP 7.0.8 on Windows gave a segfault).
Did you try stepping through php_openssl_enable_crypto[1]? In my
tests with exif_read_data(), cert_captured never got assigned
(because stream->context was NULL), but it was tested on line
1791[2].
When I used file_get_contents() instead of exif_read_data() in the
reproduce script, stream->context was set, so cert_captured is
properly initialized, but still valgrind reported memory leaks.
[1] <https://github.com/php/php-src/blob/PHP-5.6.24/ext/openssl/xp_ssl.c#L1669>
[2] <https://github.com/php/php-src/blob/PHP-5.6.24/ext/openssl/xp_ssl.c#L1791>
Previous Comments:
------------------------------------------------------------------------
[2016-08-01 08:41:30] romans dot heimanis at gmail dot com
Just changing original e-mail
------------------------------------------------------------------------
[2016-08-01 06:18:52] stas@php.net
Sorry, unable to reproduce any issues on either 5.6 or 7.0 with either bad_exif.jpeg or 62523.jpg.
No segfaults, not complaints, nothing.
------------------------------------------------------------------------
[2016-08-01 02:56:51] stas@php.net
I'm not sure what this has to do with openssl (given that the URL is not HTTPS). But I'll
check what happens with these images.
------------------------------------------------------------------------
[2016-07-31 11:56:30] cmb@php.net
<?php
exif_read_data('http://dl.dropbox.com/u/7562584/Bugs/Php/bad_exif.jpeg');
Indeed, valgrind reports
| Conditional jump or move depends on uninitialised value(s)
In this case cert_captured is uninitialized in the check whether
peer_cert has to be freed[1]. After adding a proper initializer,
there are still memory leaks reported by valgrind (also when
file_get_contents() is used instead of exif_read_data() with the
unmodified C code).
Stas, could you have a look at this issue?
[1] <https://github.com/php/php-src/blob/PHP-7.0.9/ext/openssl/xp_ssl.c#L1893>
------------------------------------------------------------------------
[2016-07-31 04:22:24] php-bugs at lists dot php dot net
No feedback was provided. The bug is being suspended because
we assume that you are no longer experiencing the problem.
If this is not the case and you are able to provide the
information that was requested earlier, please do so and
change the status of the bug back to "Re-Opened". Thank you.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=62523
--
Edit this bug report at https://bugs.php.net/bug.php?id=62523&edit=1