Bug #76068 [Opn->Ana]: parse_ini_string fails to parse "[foo]\nbar=1|>baz" with segfault
| From: | cmb@php.net | Date: | Thu, 08 Mar 2018 16:07:52 +0000 |
| Subject: | Bug #76068 [Opn->Ana]: parse_ini_string fails to parse "[foo]\nbar=1|>baz" with segfault | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-214238@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=76068&edit=1
ID: 76068
Updated by: cmb@php.net
Reported by: madboyka at yahoo dot com
Summary: parse_ini_string fails to parse "[foo]\nbar=1|>baz"
with segfault
-Status: Open
+Status: Analyzed
Type: Bug
Package: Filesystem function related
Operating System: Windows 10
PHP Version: 7.2.3
Block user comment: N
Private report: N
New Comment:
> the code should run without errors and return
> ['foo'=> ['bar' => '1|>baz']]
Assuming this return value would be incorrect, since the
documentation[1] states:
| If a value in the ini file contains any non-alphanumeric
| characters it needs to be enclosed in double-quotes (").
However, a segfault must indeed not occur here.
The problem is that
zend_ini_do_op() assumes that the operands
are strings[2], which is wrong, since in case of the given
reproduce script, op1 IS_LONG.
[1] <http://www.php.net/manual/en/function.parse-ini-file.php#refsect1-function.parse-ini-file-notes>
[2] <https://github.com/php/php-src/blob/php-7.2.3/Zend/zend_ini_parser.y#L60-L63>
Previous Comments:
------------------------------------------------------------------------
[2018-03-08 14:26:21] madboyka at yahoo dot com
Description:
------------
Trying to parse the value "[foo]\nbar=1|>baz" with process_sections = true and
scanner_mode = INI_SCANNER_TYPED causes a segmentation fault in the php process.
Looks like PHP sees the | as a logical operator and tries to do something with it.
Doesn't matter whether parse_ini_string or parse_ini_file is used.
I tried this on:
Windows 10 with PHP 7.2.3
Ubuntu 16.04 with PHP 7.1.14-1+ubuntu16.04.1+deb.sury.org+1
CentOS 7.4.1708 with PHP 7.1.14
Test script:
---------------
parse_ini_string("[foo]\nbar=1|>baz",true, \INI_SCANNER_TYPED);
Expected result:
----------------
the code should run without errors and return ['foo'=> ['bar' =>
'1|>baz']]
Actual result:
--------------
produces segmentation fault
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=76068&edit=1