Bug #77697 [NEW]: Crash on Big_Endian platform

From: Date: Tue, 05 Mar 2019 15:14:06 +0000
Subject: Bug #77697 [NEW]: Crash on Big_Endian platform
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-219851@lists.php.net to get a copy of this message
From: samding at ca dot ibm dot com Operating system: Linux PHP version: 7.3.2 Package: PHAR related Bug Type: Bug Bug description:Crash on Big_Endian platform Description: ------------ Test case: ext/phar/tests/phar_setsignaturealgo2.phpt has a core dump on Big-Endian platform. The Problem code is in "ext/phar/util.c": 1880 1881 if (!EVP_SignFinal (md_ctx, sigbuf,(unsigned int *)&siglen, key)) { 1882 efree(sigbuf); 1883 if (error) { 1884 spprintf(error, 0, "unable to write phar \"%s\" with requested openssl signature", phar->fname); 1885 } 1886 return FAILURE; 1887 } 1888 1889 sigbuf[siglen] = '\0'; // siglen is out of boundary, leads to a core dump 1890 EVP_MD_CTX_destroy(md_ctx); Debugger shows: (gdb) p siglen $1 = 549755814016 The reason is that "siglen" is defined as "size_t" (unsigned long), but in line 1881, when calling "EVP_SignFinal", it is cast-ed to "unsigned int" by pointer, which means to take the first 4 bytes in passing to "EVP_SignFinal". This is not a problem on Little_Endian platform, but has an issue on Big_endian platform, and caused the returned "siglen" in a large value. One of the solution is to define "siglen" as "unsigned int" instead of "size_t". Test script: --------------- ./sapi/cli/php run-tests.php -P ext/phar/tests/phar_setsignaturealgo2.phpt Expected result: ---------------- "siglen" should be returned as an index value. Actual result: -------------- (gdb) p siglen $1 = 549755814016 // wrong index value -- Edit bug report at https://bugs.php.net/bug.php?id=77697&edit=1 -- Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=77697&r=trysnapshot54 Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=77697&r=trysnapshot55 Try a snapshot (trunk): https://bugs.php.net/fix.php?id=77697&r=trysnapshottrunk Fixed in SVN: https://bugs.php.net/fix.php?id=77697&r=fixed Fixed in release: https://bugs.php.net/fix.php?id=77697&r=alreadyfixed Need backtrace: https://bugs.php.net/fix.php?id=77697&r=needtrace Need Reproduce Script: https://bugs.php.net/fix.php?id=77697&r=needscript Try newer version: https://bugs.php.net/fix.php?id=77697&r=oldversion Not developer issue: https://bugs.php.net/fix.php?id=77697&r=support Expected behavior: https://bugs.php.net/fix.php?id=77697&r=notwrong Not enough info: https://bugs.php.net/fix.php?id=77697&r=notenoughinfo Submitted twice: https://bugs.php.net/fix.php?id=77697&r=submittedtwice register_globals: https://bugs.php.net/fix.php?id=77697&r=globals PHP 4 support discontinued: https://bugs.php.net/fix.php?id=77697&r=php4 Daylight Savings: https://bugs.php.net/fix.php?id=77697&r=dst IIS Stability: https://bugs.php.net/fix.php?id=77697&r=isapi Install GNU Sed: https://bugs.php.net/fix.php?id=77697&r=gnused Floating point limitations: https://bugs.php.net/fix.php?id=77697&r=float No Zend Extensions: https://bugs.php.net/fix.php?id=77697&r=nozend MySQL Configuration Error: https://bugs.php.net/fix.php?id=77697&r=mysqlcfg

« previous php.bugs (#219851) next »