Bug #76068 [Opn->Ana]: parse_ini_string fails to parse "[foo]\nbar=1|>baz" with segfault

From: Date: Thu, 08 Mar 2018 16:07:52 +0000
Subject: Bug #76068 [Opn->Ana]: parse_ini_string fails to parse "[foo]\nbar=1|>baz" with segfault
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-214238@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=76068&edit=1 ID: 76068 Updated by: cmb@php.net Reported by: madboyka at yahoo dot com Summary: parse_ini_string fails to parse "[foo]\nbar=1|>baz" with segfault -Status: Open +Status: Analyzed Type: Bug Package: Filesystem function related Operating System: Windows 10 PHP Version: 7.2.3 Block user comment: N Private report: N New Comment: > the code should run without errors and return > ['foo'=> ['bar' => '1|>baz']] Assuming this return value would be incorrect, since the documentation[1] states: | If a value in the ini file contains any non-alphanumeric | characters it needs to be enclosed in double-quotes ("). However, a segfault must indeed not occur here. The problem is that zend_ini_do_op() assumes that the operands are strings[2], which is wrong, since in case of the given reproduce script, op1 IS_LONG. [1] <http://www.php.net/manual/en/function.parse-ini-file.php#refsect1-function.parse-ini-file-notes> [2] <https://github.com/php/php-src/blob/php-7.2.3/Zend/zend_ini_parser.y#L60-L63> Previous Comments: ------------------------------------------------------------------------ [2018-03-08 14:26:21] madboyka at yahoo dot com Description: ------------ Trying to parse the value "[foo]\nbar=1|>baz" with process_sections = true and scanner_mode = INI_SCANNER_TYPED causes a segmentation fault in the php process. Looks like PHP sees the | as a logical operator and tries to do something with it. Doesn't matter whether parse_ini_string or parse_ini_file is used. I tried this on: Windows 10 with PHP 7.2.3 Ubuntu 16.04 with PHP 7.1.14-1+ubuntu16.04.1+deb.sury.org+1 CentOS 7.4.1708 with PHP 7.1.14 Test script: --------------- parse_ini_string("[foo]\nbar=1|>baz",true, \INI_SCANNER_TYPED); Expected result: ---------------- the code should run without errors and return ['foo'=> ['bar' => '1|>baz']] Actual result: -------------- produces segmentation fault ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=76068&edit=1

« previous php.bugs (#214238) next »