Bug #62523 [Asn->Csd]: php crashes with segfault when exif_read_data called
| From: | stas@php.net | Date: | Mon, 01 Aug 2016 17:24:35 +0000 |
| Subject: | Bug #62523 [Asn->Csd]: php crashes with segfault when exif_read_data called | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-202805@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=62523&edit=1
ID: 62523
Updated by: stas@php.net
Reported by: romans dot heimanis at gmail dot com
Summary: php crashes with segfault when exif_read_data called
-Status: Assigned
+Status: Closed
Type: Bug
Package: Reproducible crash
Operating System: linux
PHP Version: 5.6.23
Assigned To: stas
Block user comment: N
Private report: N
New Comment:
If exif it fine with the file data, then this is another bug for sure. Let's open a new issue
and add specific info regarding the backtraces, valgrind output and such.
Previous Comments:
------------------------------------------------------------------------
[2016-08-01 09:49:36] cmb@php.net
> I'm not sure what this has to do with openssl (given that the
> URL is not HTTPS).
$ curl -I -s http://dl.dropbox.com/u/7562584/Bugs/Php/bad_exif.jpeg'
| grep location
location: http://dl.dropboxusercontent.com/u/7562584/Bugs/Php/bad_exif.jpeg
> Sorry, unable to reproduce any issues on either 5.6 or 7.0 with
> either bad_exif.jpeg or 62523.jpg.
Reading the exif data from a local file shows no issues; the
problem is with the connection to the server. I've tested and
debugged with the 5.6 branch, but I assume the issue occurs also
with newer versions (PHP 7.0.8 on Windows gave a segfault).
Did you try stepping through php_openssl_enable_crypto[1]? In my
tests with exif_read_data(), cert_captured never got assigned
(because stream->context was NULL), but it was tested on line
1791[2].
When I used file_get_contents() instead of exif_read_data() in the
reproduce script, stream->context was set, so cert_captured is
properly initialized, but still valgrind reported memory leaks.
[1] <https://github.com/php/php-src/blob/PHP-5.6.24/ext/openssl/xp_ssl.c#L1669>
[2] <https://github.com/php/php-src/blob/PHP-5.6.24/ext/openssl/xp_ssl.c#L1791>
------------------------------------------------------------------------
[2016-08-01 08:41:30] romans dot heimanis at gmail dot com
Just changing original e-mail
------------------------------------------------------------------------
[2016-08-01 06:18:52] stas@php.net
Sorry, unable to reproduce any issues on either 5.6 or 7.0 with either bad_exif.jpeg or 62523.jpg.
No segfaults, not complaints, nothing.
------------------------------------------------------------------------
[2016-08-01 02:56:51] stas@php.net
I'm not sure what this has to do with openssl (given that the URL is not HTTPS). But I'll
check what happens with these images.
------------------------------------------------------------------------
[2016-07-31 11:56:30] cmb@php.net
<?php
exif_read_data('http://dl.dropbox.com/u/7562584/Bugs/Php/bad_exif.jpeg');
Indeed, valgrind reports
| Conditional jump or move depends on uninitialised value(s)
In this case cert_captured is uninitialized in the check whether
peer_cert has to be freed[1]. After adding a proper initializer,
there are still memory leaks reported by valgrind (also when
file_get_contents() is used instead of exif_read_data() with the
unmodified C code).
Stas, could you have a look at this issue?
[1] <https://github.com/php/php-src/blob/PHP-7.0.9/ext/openssl/xp_ssl.c#L1893>
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=62523
--
Edit this bug report at https://bugs.php.net/bug.php?id=62523&edit=1