Edit report at https://bugs.php.net/bug.php?id=73361&edit=1
ID: 73361
User updated by: 271193918 at qq dot com
Reported by: 271193918 at qq dot com
Summary: Out-of-bounds reads issue of php 5.6.27
-Status: Feedback
+Status: Assigned
Type: Bug
Package: Scripting Engine problem
Operating System: Ubuntu 16.04 x86
PHP Version: 5.6.27
Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
The link to image id_000194,sig_11,src_024221+025505,op_splice,rep_2 is:
https://mega.nz/#!AxxAzCwZ!Sx6BQTyzZupL2sCeyYLK628sJChx6eN8D754zh0Xh00
Previous Comments:
------------------------------------------------------------------------
[2016-10-25 15:16:45] cmb@php.net
To be able to debug this issue we need a copy of
./crashes/fuzzer01/id_000194,sig_11,src_024221+025505,op_splice,rep_2
------------------------------------------------------------------------
[2016-10-24 06:26:58] stas@php.net
Maybe a weird parser bug, certainly not a security issue - nobody runs binary junk as PHP script.
------------------------------------------------------------------------
[2016-10-24 06:26:02] stas@php.net
Wait, I just noticed. Why you use php -c option? This makes php read exif_read_data.php as config
file and ./crashes/fuzzer01/id_000194,sig_11,src_024221+025505,op_splice,rep_2 as a script.
That's not how it's usually supposed to work.
------------------------------------------------------------------------
[2016-10-24 06:24:49] stas@php.net
I don't see any problem in the valgrind report what exactly are you reproducing?
Also, could you provide a link to the file:
./crashes/fuzzer01/id_000194,sig_11,src_024221+025505,op_splice,rep_2
------------------------------------------------------------------------
[2016-10-24 06:22:02] 271193918 at qq dot com
If compile php 5.6.27 with Asan:
run without USE_ZEND_ALLOC=0 , test log as follows:
./php -c ./crashes/exif_read_data.php
./crashes/fuzzer01/id_000194,sig_11,src_024221+025505,op_splice,rep_2
Fatal error: Allowed memory size of 134217728 bytes exhausted at
/home/test/Desktop/php_test/php-5.6.27-gcc-Asan/Zend/zend_vm_execute.h:12902 (tried to allocate
27751964 bytes) in
/home/test/Desktop/php_test/php-5.6.27-gcc-Asan/sapi/cli/crashes/fuzzer01/id_000194,sig_11,src_024221+025505,op_splice,rep_2
on line 65
ASAN:SIGSEGV
=================================================================
==18377==ERROR: AddressSanitizer: SEGV on unknown address 0xa70bce4b (pc 0x08b06f17 bp 0xbfbf2b98 sp
0xbfbf2b70 T0)
#0 0x8b06f16 in _zval_dtor_func
/home/test/Desktop/php_test/php-5.6.27-gcc-Asan/Zend/zend_variables.c:36
#1 0x8aca1af in _zval_dtor
/home/test/Desktop/php_test/php-5.6.27-gcc-Asan/Zend/zend_variables.h:35
#2 0x8aca2bd in i_zval_ptr_dtor
/home/test/Desktop/php_test/php-5.6.27-gcc-Asan/Zend/zend_execute.h:79
#3 0x8acd46f in _zval_ptr_dtor
/home/test/Desktop/php_test/php-5.6.27-gcc-Asan/Zend/zend_execute_API.c:424
#4 0x8b07ce6 in _zval_ptr_dtor_wrapper
/home/test/Desktop/php_test/php-5.6.27-gcc-Asan/Zend/zend_variables.c:188
#5 0x8b40672 in i_zend_hash_bucket_delete
/home/test/Desktop/php_test/php-5.6.27-gcc-Asan/Zend/zend_hash.c:182
#6 0x8b4082e in zend_hash_bucket_delete
/home/test/Desktop/php_test/php-5.6.27-gcc-Asan/Zend/zend_hash.c:192
#7 0x8b4639a in zend_hash_graceful_reverse_destroy
/home/test/Desktop/php_test/php-5.6.27-gcc-Asan/Zend/zend_hash.c:613
#8 0x8acc193 in shutdown_executor
/home/test/Desktop/php_test/php-5.6.27-gcc-Asan/Zend/zend_execute_API.c:244
#9 0x8b0dc11 in zend_deactivate /home/test/Desktop/php_test/php-5.6.27-gcc-Asan/Zend/zend.c:960
#10 0x89a6b76 in php_request_shutdown
/home/test/Desktop/php_test/php-5.6.27-gcc-Asan/main/main.c:1899
#11 0x8d6e3d9 in do_cli /home/test/Desktop/php_test/php-5.6.27-gcc-Asan/sapi/cli/php_cli.c:1181
#12 0x8d6f0bd in main /home/test/Desktop/php_test/php-5.6.27-gcc-Asan/sapi/cli/php_cli.c:1382
#13 0xb6ba3636 in __libc_start_main (/lib/i386-linux-gnu/libc.so.6+0x18636)
#14 0x8067730 (/home/test/Desktop/php_test/php-5.6.27-gcc-Asan/sapi/cli/php+0x8067730)
AddressSanitizer can not provide additional info.
SUMMARY: AddressSanitizer: SEGV
/home/test/Desktop/php_test/php-5.6.27-gcc-Asan/Zend/zend_variables.c:36 _zval_dtor_func
==18377==ABORTING
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=73361
--
Edit this bug report at https://bugs.php.net/bug.php?id=73361&edit=1