Bug #62523 [Asn->Csd]: php crashes with segfault when exif_read_data called

From: Date: Mon, 01 Aug 2016 17:24:35 +0000
Subject: Bug #62523 [Asn->Csd]: php crashes with segfault when exif_read_data called
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-202805@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=62523&edit=1 ID: 62523 Updated by: stas@php.net Reported by: romans dot heimanis at gmail dot com Summary: php crashes with segfault when exif_read_data called -Status: Assigned +Status: Closed Type: Bug Package: Reproducible crash Operating System: linux PHP Version: 5.6.23 Assigned To: stas Block user comment: N Private report: N New Comment: If exif it fine with the file data, then this is another bug for sure. Let's open a new issue and add specific info regarding the backtraces, valgrind output and such. Previous Comments: ------------------------------------------------------------------------ [2016-08-01 09:49:36] cmb@php.net > I'm not sure what this has to do with openssl (given that the > URL is not HTTPS). $ curl -I -s http://dl.dropbox.com/u/7562584/Bugs/Php/bad_exif.jpeg' | grep location location: http://dl.dropboxusercontent.com/u/7562584/Bugs/Php/bad_exif.jpeg > Sorry, unable to reproduce any issues on either 5.6 or 7.0 with > either bad_exif.jpeg or 62523.jpg. Reading the exif data from a local file shows no issues; the problem is with the connection to the server. I've tested and debugged with the 5.6 branch, but I assume the issue occurs also with newer versions (PHP 7.0.8 on Windows gave a segfault). Did you try stepping through php_openssl_enable_crypto[1]? In my tests with exif_read_data(), cert_captured never got assigned (because stream->context was NULL), but it was tested on line 1791[2]. When I used file_get_contents() instead of exif_read_data() in the reproduce script, stream->context was set, so cert_captured is properly initialized, but still valgrind reported memory leaks. [1] <https://github.com/php/php-src/blob/PHP-5.6.24/ext/openssl/xp_ssl.c#L1669> [2] <https://github.com/php/php-src/blob/PHP-5.6.24/ext/openssl/xp_ssl.c#L1791> ------------------------------------------------------------------------ [2016-08-01 08:41:30] romans dot heimanis at gmail dot com Just changing original e-mail ------------------------------------------------------------------------ [2016-08-01 06:18:52] stas@php.net Sorry, unable to reproduce any issues on either 5.6 or 7.0 with either bad_exif.jpeg or 62523.jpg. No segfaults, not complaints, nothing. ------------------------------------------------------------------------ [2016-08-01 02:56:51] stas@php.net I'm not sure what this has to do with openssl (given that the URL is not HTTPS). But I'll check what happens with these images. ------------------------------------------------------------------------ [2016-07-31 11:56:30] cmb@php.net <?php exif_read_data('http://dl.dropbox.com/u/7562584/Bugs/Php/bad_exif.jpeg'); Indeed, valgrind reports | Conditional jump or move depends on uninitialised value(s) In this case cert_captured is uninitialized in the check whether peer_cert has to be freed[1]. After adding a proper initializer, there are still memory leaks reported by valgrind (also when file_get_contents() is used instead of exif_read_data() with the unmodified C code). Stas, could you have a look at this issue? [1] <https://github.com/php/php-src/blob/PHP-7.0.9/ext/openssl/xp_ssl.c#L1893> ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=62523 -- Edit this bug report at https://bugs.php.net/bug.php?id=62523&edit=1

« previous php.bugs (#202805) next »