Bug #77962 [Fbk->Asn]: finfo_open crafted magic parsing SIGFPE
| From: | radimre83 at gmail dot com | Date: | Tue, 09 Nov 2021 10:25:33 +0000 |
| Subject: | Bug #77962 [Fbk->Asn]: finfo_open crafted magic parsing SIGFPE | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-237644@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=77962&edit=1
ID: 77962
User updated by: radimre83 at gmail dot com
Reported by: radimre83 at gmail dot com
Summary: finfo_open crafted magic parsing SIGFPE
-Status: Feedback
+Status: Assigned
Type: Bug
Package: Filesystem function related
Operating System: Linux
PHP Version: 7.3.5
Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
Hi,
I did not follow up on this at all.
Previous Comments:
------------------------------------------------------------------------
[2021-11-09 09:36:42] cmb@php.net
> I'd suggest to go upstream first, then we could land a patch if
> suitable.
Has this issue been reported upstream? If so, what was the outcome?
------------------------------------------------------------------------
[2019-05-06 00:40:00] stas@php.net
Please do not reclassify this bug again. If in doubt, please read https://wiki.php.net/security
------------------------------------------------------------------------
[2019-05-05 17:37:55] radimre83 at gmail dot com
Ah sorry, I didnt notice the comments (did not receive any email notifications about them...), and
now I cannot revert it back to Bug.
------------------------------------------------------------------------
[2019-05-05 17:35:39] radimre83 at gmail dot com
Changing bug type to security.
------------------------------------------------------------------------
[2019-05-02 20:16:38] ab@php.net
Hi,
thanks for the report. If garbage or incompatible data was passed to libmagic, any kinds of issues
are just expected. PHP supplies the curated magic data which guarantees compatibility. Otherwise
it's user responsibility, if external file is needed. So it is for sure not a security issue.
Furthermore, crash just reflects what happens in libmagic. This is the way how libmagic works and
similar behaviors has been sighted in previous versions. I'd suggest to go upstream first, then
we could land a patch if suitable.
Thanks.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=77962
--
Edit this bug report at https://bugs.php.net/bug.php?id=77962&edit=1