Bug #76276 [Opn->Wfx]: PCRE Segmentation fault before PHP7

From: Date: Fri, 27 Apr 2018 14:47:30 +0000
Subject: Bug #76276 [Opn->Wfx]: PCRE Segmentation fault before PHP7
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-214938@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=76276&edit=1

 ID:                 76276
 Updated by:         nikic@php.net
 Reported by:        drealecs at gmail dot com
 Summary:            PCRE Segmentation fault before PHP7
-Status:             Open
+Status:             Wont fix
 Type:               Bug
 Package:            PCRE related
 Operating System:   Linux
 PHP Version:        5.6.36
 Block user comment: N
 Private report:     N

 New Comment:

This is a classical PCRE stack overflow. PHP 7 is not affected because it uses PCRE JIT by default.
The crash can still be reproduced under pcre.jit=0. On PHP 7.3 the issue has been resolved entirely
as part of the upgrade to PCRE2, which moved to a non-recursive implementation of the non-JIT
matcher in version 10.30.

In any case, PHP 5 is no longer supported for non-security issues and this is not a security issue.


Previous Comments:
------------------------------------------------------------------------
[2018-04-27 14:41:21] spam2 at rhsoft dot net

> There seems to be a buffer overflow in all 
> PHP version 4.* and 5.* but not on PHP 7.*

so why do you bother to write a new bugreport at 2018-04-27 given that the only 2 supported versions
are 7.1 and 7.2?

------------------------------------------------------------------------
[2018-04-27 14:37:55] drealecs at gmail dot com

https://3v4l.org/RJt1X

------------------------------------------------------------------------
[2018-04-27 14:36:34] drealecs at gmail dot com

Description:
------------
There seems to be a buffer overflow in all PHP version 4.* and 5.*
but not on PHP 7.*

Test script:
---------------
$string = '';
for ($i = 0; $i < 10000; $i++) {
    $string .= chr(rand(65, 122));
}
echo "Calling preg_match_all()\n";
preg_match_all('/(\D|3)*/', $string, $matches);

echo "It didn't broke php\n";


Expected result:
----------------
Calling preg_match_all()
It didn't broke php

Actual result:
--------------
Calling preg_match_all()

Segmentation fault


------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=76276&edit=1


Thread (4 messages)

« previous php.bugs (#214938) next »