Edit report at https://bugs.php.net/bug.php?id=80817&edit=1
ID: 80817
Updated by: cmb@php.net
Reported by: cmb@php.net
Summary: dba_popen() may cause segfault during RSHUTDOWN
Status: Assigned
Type: Bug
Package: DBM/DBA related
Operating System: Windows
PHP Version: 7.4Git-2021-03-01 (Git)
Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
Thanks, Stas!
Previous Comments:
------------------------------------------------------------------------
[2021-03-15 17:17:43] stas@php.net
I think we can merge the fix.
------------------------------------------------------------------------
[2021-03-15 10:58:49] cmb@php.net
If this is not a security issue, it would be good to merge the
patch today, or early tomorrow, so it can be rolled out with the
RCs.
------------------------------------------------------------------------
[2021-03-02 10:24:56] cmb@php.net
A simple dba_popen() call followed by dba_close() is enough to
*sometimes* cause this misbehavior. The mentioned test fails on
AppVeyor occassionally:
<https://ci.appveyor.com/project/php/php-src/history>.
------------------------------------------------------------------------
[2021-03-02 01:32:24] stas@php.net
I'm not sure how this can be triggered - can you only trigger it with specific code or it could
be triggered by the outside user somehow? From the look of it it seems like it requires very
specific code to trigger, so it seems not to fit the security issue profile, unless there's a
way outside user action can trigger it in proper code too.
------------------------------------------------------------------------
[2021-03-01 17:28:00] cmb@php.net
Suggested fix: <https://gist.github.com/cmb69/82c0511b5cee0ea12b9507e61d5bba4a>.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=80817
--
Edit this bug report at https://bugs.php.net/bug.php?id=80817&edit=1