Bug #78878 [Com]: Buffer underflow in bc_shift_addsub
| From: | thomas-josef dot riedmaier at siemens dot com | Date: | Fri, 29 Nov 2019 08:48:57 +0000 |
| Subject: | Bug #78878 [Com]: Buffer underflow in bc_shift_addsub | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-223934@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=78878&edit=1
ID: 78878
Comment by: thomas-josef dot riedmaier at siemens dot com
Reported by: thomas-josef dot riedmaier at siemens dot com
Summary: Buffer underflow in bc_shift_addsub
Status: Feedback
Type: Bug
Package: BC math related
Operating System: Windows
PHP Version: 7.4.0
Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
If you need a test setup in which the bug can be reproduced go to
https://developer.microsoft.com/en-us/microsoft-edge/tools/vms/
and download the "IE11 on Win7 (x86)" machine.
You need to install VC Redistributables, but then you are good to go.
Previous Comments:
------------------------------------------------------------------------
[2019-11-29 07:37:54] thomas-josef dot riedmaier at siemens dot com
I digged a little bit into this and it appears to be a system-dependent problem.
When running the script with Windows7 SP1 or Windows Server 2016 (1607), the script says
"Warning: Use of undefined constant �6483605105519922841849335928742092 - assumed
'�6483605105519922841849335928742092'" and crashes.
Note the non printable character here.
When running the script with Windows 10 (1809), the scipt says "Warning: Use of undefined
constant 6483605105519922841849335928742092 - assumed
'6483605105519922841849335928742092'" and does not crash.
Note that there is no unprintable character here.
So it appears to me that depending on the Windows setup, php seem to ignore the '²', or
not. If it is not ignored, an access violation occurs.
------------------------------------------------------------------------
[2019-11-28 16:02:31] cmb@php.net
I cannot reproduce the access violation (neither with the given
code, nor when I replace the ² with 2, nor when I just remove the
²). And neither does the assertion trigger in a debug build for
me (it won't trigger in release builds anyway).
Could you please fix/clarify the test script?
------------------------------------------------------------------------
[2019-11-28 15:03:45] thomas-josef dot riedmaier at siemens dot com
Description:
------------
When executing the test snippet below, a buffer underflow occurs in bc_shift_addsub.
I theory, bc_shift_addsub's assert statement would be triggered, but this does not play any
role in the official windows release binaries https://windows.php.net/downloads/releases/php-7.4.0-Win32-vc15-x64.zip
.
Instead, on our test machines, an ACCESS_VIOLATION is triggered.
Test script:
---------------
<?php
print bcmul(²6483605105519922841849335928742092, bcpowmod(2, 65535, -4e-4));
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=78878&edit=1