Bug #77961 [Ver->Csd]: finfo_open crafted magic parsing SIGABRT

From: Date: Tue, 24 Nov 2020 13:08:14 +0000
Subject: Bug #77961 [Ver->Csd]: finfo_open crafted magic parsing SIGABRT
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-230575@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=77961&edit=1

 ID:                 77961
 Updated by:         cmb@php.net
 Reported by:        radimre83 at gmail dot com
 Summary:            finfo_open crafted magic parsing SIGABRT
-Status:             Verified
+Status:             Closed
 Type:               Bug
 Package:            Filesystem function related
 Operating System:   Linux Debian
 PHP Version:        7.3.5
 Assigned To:        cmb
 Block user comment: N
 Private report:     N

 New Comment:

Automatic comment on behalf of cmbecker69@gmx.de
Revision: http://git.php.net/?p=php-src.git;a=commit;h=39f95f56144d595b9af7828726c3e28c313fb2b7
Log: Fix #77961: finfo_open crafted magic parsing SIGABRT


Previous Comments:
------------------------------------------------------------------------
[2020-11-19 13:17:58] cmb@php.net

The following pull request has been associated:

Patch Name: Fix #77961: finfo_open crafted magic parsing SIGABRT
On GitHub:  https://github.com/php/php-src/pull/6437
Patch:      https://github.com/php/php-src/pull/6437.patch

------------------------------------------------------------------------
[2020-11-18 15:51:00] cmb@php.net

> Note: there are quite a few abort() calls in the source code.

Yes, and that is bad.  I think we should just E_ERROR instead.

------------------------------------------------------------------------
[2019-05-16 13:39:28] spam2 at rhsoft dot net

yesh, I can write nice documents amending nonsense while in the rest of the world any crash bug is a
security bug - shared hosters will say thank you when a customer ftp account not hacked only god
knows where the guy is which triggers a bug which won't exist in a sane world

------------------------------------------------------------------------
[2019-05-16 11:00:26] radimre83 at gmail dot com

spam2 at rhsoft dot net: See the consideration here: 

https://bugs.php.net/bug.php?id=77962

------------------------------------------------------------------------
[2019-05-16 09:36:59] spam2 at rhsoft dot net

damned how is it not a security bug when one can crash server processes by arbitrary input to
functions which are used to check and reject uploads

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=77961


--
Edit this bug report at https://bugs.php.net/bug.php?id=77961&edit=1


Thread (1 message)

  • cmb@php.net
  • Unknown Message
    • cmb@php.net
« previous php.bugs (#230575) next »