Edit report at https://bugs.php.net/bug.php?id=77961&edit=1
ID: 77961
Updated by: cmb@php.net
Reported by: radimre83 at gmail dot com
Summary: finfo_open crafted magic parsing SIGABRT
-Status: Verified
+Status: Closed
Type: Bug
Package: Filesystem function related
Operating System: Linux Debian
PHP Version: 7.3.5
Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
Automatic comment on behalf of cmbecker69@gmx.de
Revision: http://git.php.net/?p=php-src.git;a=commit;h=39f95f56144d595b9af7828726c3e28c313fb2b7
Log: Fix #77961: finfo_open crafted magic parsing SIGABRT
Previous Comments:
------------------------------------------------------------------------
[2020-11-19 13:17:58] cmb@php.net
The following pull request has been associated:
Patch Name: Fix #77961: finfo_open crafted magic parsing SIGABRT
On GitHub: https://github.com/php/php-src/pull/6437
Patch: https://github.com/php/php-src/pull/6437.patch
------------------------------------------------------------------------
[2020-11-18 15:51:00] cmb@php.net
> Note: there are quite a few abort() calls in the source code.
Yes, and that is bad. I think we should just E_ERROR instead.
------------------------------------------------------------------------
[2019-05-16 13:39:28] spam2 at rhsoft dot net
yesh, I can write nice documents amending nonsense while in the rest of the world any crash bug is a
security bug - shared hosters will say thank you when a customer ftp account not hacked only god
knows where the guy is which triggers a bug which won't exist in a sane world
------------------------------------------------------------------------
[2019-05-16 11:00:26] radimre83 at gmail dot com
spam2 at rhsoft dot net: See the consideration here:
https://bugs.php.net/bug.php?id=77962
------------------------------------------------------------------------
[2019-05-16 09:36:59] spam2 at rhsoft dot net
damned how is it not a security bug when one can crash server processes by arbitrary input to
functions which are used to check and reject uploads
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=77961
--
Edit this bug report at https://bugs.php.net/bug.php?id=77961&edit=1