Bug #73103 [Opn->Csd]: Release 1.1.0 has random behaviour

From: Date: Sun, 18 Sep 2016 10:54:19 +0000
Subject: Bug #73103 [Opn->Csd]: Release 1.1.0 has random behaviour
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-204108@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=73103&edit=1

 ID:                 73103
 User updated by:    tvdijen at gmail dot com
 Reported by:        tvdijen at gmail dot com
 Summary:            Release 1.1.0 has random behaviour
-Status:             Open
+Status:             Closed
 Type:               Bug
 Package:            *General Issues
 Operating System:   CentOS 7 + RHEL6
 PHP Version:        Irrelevant
 Block user comment: N
 Private report:     N

 New Comment:

Thanks Moritz!


Previous Comments:
------------------------------------------------------------------------
[2016-09-17 19:17:09] mbechler at eenterphace dot org

Commited a fix to SVN. Thanks for the patch, but I don't think it's
quite right - the problem is that the base64 encoded buffer is not zero
terminated anymore after the 1.1 changes (wrapping in zend_string) so
the strcpy overflows the allocated buffer (the size is correct). Fixed
that by properly using strncpy.

I guess this can be closed (and if someone can tell me how to get a bug category and developer
access to it, that would be great).

------------------------------------------------------------------------
[2016-09-17 16:15:22] tvdijen at gmail dot com

Proposed fix:
https://github.com/tvdijen/krb5/commit/e932d7a4240aac75c5bfe930f20033b4aee7c601

This fixed the problem for me. I think it needs space for a trailing null-character.

------------------------------------------------------------------------
[2016-09-17 14:57:11] tvdijen at gmail dot com

Yet another update:
I've managed to narrow it down to the strcpy lines at the bottom of the
doAuthentication-function. Specifically the second one.
Whenever I put in a RETURN_TRUE; above these lines, everything is working fine. When I put it
underneath, de segfault is showing up again.

------------------------------------------------------------------------
[2016-09-17 12:25:23] tvdijen at gmail dot com

I was also able to lift this error from /var/log/httpd/error.log:

[Sat Sep 17 14:22:10.007578 2016] [core:notice] [pid 2914] AH00052: child pid 2920 exit signal
Segmentation fault (11)

------------------------------------------------------------------------
[2016-09-17 11:39:28] tvdijen at gmail dot com

This should be connected to the krb5-module: https://pecl.php.net/package/krb5
It somehow failed to do so.

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=73103


--
Edit this bug report at https://bugs.php.net/bug.php?id=73103&edit=1


Thread (7 messages)

« previous php.bugs (#204108) next »