Bug #74947 [Opn->Csd]: Segfault in scanner on INF number
| From: | laruence@php.net | Date: | Fri, 21 Jul 2017 04:05:14 +0000 |
| Subject: | Bug #74947 [Opn->Csd]: Segfault in scanner on INF number | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-210156@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=74947&edit=1
ID: 74947
Updated by: laruence@php.net
Reported by: geeknik at protonmail dot ch
Summary: Segfault in scanner on INF number
-Status: Open
+Status: Closed
Type: Bug
Package: Reproducible crash
Operating System: Fedora 26 x64
PHP Version: 7.1.7
Block user comment: N
Private report: N
New Comment:
Automatic comment on behalf of laruence@gmail.com
Revision: http://git.php.net/?p=php-src.git;a=commit;h=95d2908814585bd9c3c9a1eab4989bc551b6cc73
Log: Fixed bug #74947 (Segfault in scanner on INF number)
Previous Comments:
------------------------------------------------------------------------
[2017-07-19 06:06:24] geeknik at protonmail dot ch
Description:
------------
Built with afl-clang-fast and ASan/UBSan on Fedora 26 x64. While fuzzing with AFL this runtime error
was triggered.
Test script:
---------------
<?200000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000[
Expected result:
----------------
Business as usual.
Actual result:
--------------
Zend/zend_string.h:122:36: runtime error: member access within null pointer of type
'zend_string' (aka 'struct _zend_string')
#0 0x1f0480c in zend_string_alloc /root/php-7.1.7/Zend/zend_string.h:122:36
#1 0x1f0480c in zend_string_init /root/php-7.1.7/Zend/zend_string.h:158
#2 0x1f0480c in _zend_hash_str_add /root/php-7.1.7/Zend/zend_hash.c:666
#3 0x1ae0ac5 in zend_hash_str_add_mem /root/php-7.1.7/Zend/zend_hash.h:620:12
#4 0x1ae0ac5 in sapi_register_post_entry /root/php-7.1.7/main/SAPI.c:954
#5 0x1ae07e6 in sapi_register_post_entries /root/php-7.1.7/main/SAPI.c:940:7
#6 0x1aeea3b in php_setup_sapi_content_types /root/php-7.1.7/main/php_content_types.c:64:2
#7 0x29801ee in main /root/php-7.1.7/sapi/cli/php_cli.c:1326:2
#8 0x7f08e77424d9 in __libc_start_main (/lib64/libc.so.6+0x204d9)
#9 0x43aad9 in _start (/root/php-7.1.7/sapi/cli/php+0x43aad9)
SUMMARY: AddressSanitizer: undefined-behavior Zend/zend_string.h:122:36 in
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=74947&edit=1