From: ceo at l-i-e dot com
Operating system: FreeBSD o11.hostbaby.com 5.3-REL
PHP version: 5.1.2
PHP Bug Type: GD related
Bug description: munged JPEG + imagecreatefromstring segfault
Description:
------------
This *MAY* be the same as the bug fixed by the new GD functions, what with
GD free-ing RAM that PHP had allocated, but I suspect it is not...
Suppose a user is naive enough to not use CURLOPT_BINARYTRANSFER when
using curl to get an image.
Suppose they then pass that image string into imagecreatefromstring()
Then that user will get a segfault, most of the time.
Though not always.
Granted, this is pretty dumb thing to do, once you understand what
CURLOPT_BINARYTRANSFER is for in the first place.
But, before you grok that, it's a pretty common mistake.
Or, even if you understood it, but somehow mis-coded, or forgot it the
next time you wrote some similar code, you end up with segfaults.
And common mistakes, in an ideal world, should not segfault, but should
produce an E_ERROR (or similar).
Reproduce code:
---------------
The original code was your basic:
[Untested, really, but...]
<?php
$curl = curl_init();
curl_setopt($curl, CURLOPT_RETURNTRANSFER, 1);
curl_setopt($curl, CURLOPT_URL,
'http://bugs.php.net/gifs/logo-bug.gif');
$image_string = curl_exec($curl);
$image = imagecreatefromstring($image_string);
?>
It may be JPEG only, so you'd need to try different images instead of the
self-referenctial GIF from this page.
However, you may find it easier to just snag this jpeg:
http://acousticdemo.com/info.com/overture/jpeg_crashed/088b1cc1662339d5008fd3d67ec7cf01.jpg
which I saved from the above, and work with it.
If you simply snag that, and do:
<?php imagecreatefromstring($YOURFILE);?>
it will segfault.
I can do it from the command line every time with that file.
Yes, it *IS* a corrupt JPEG, almost for sure.
But I'm hoping it's corrupt in a detectable way, if you know what I mean,
and we can change the 'segfault' behaviour into E_ERROR behaviour.
Mozilla seems quite content to display a rendering which "looks right"
even for that corrupt image, which gives me hope that it is a detectable
error -- but also makes debugging quite difficult, since you have an image
that "looks right" but that PHP segfaults on, every time.
Here are some more sample (corrupt) images, for your convenience for
testing:
http://acousticdemo.com/info.com/overture/jpeg_crashed/
Expected result:
----------------
I expected E_ERROR for an invalid JPEG.
I don't expect it to "fix" the image the way the browsers do, though.
The scripter should be educated via E_ERROR to fix their code, rather than
have PHP fix it for, say, JPEGs, but then it fails for any custom
proprietary binary data.
Actual result:
--------------
segfault
--
Edit bug report at http://bugs.php.net/?id=37005&edit=1
--
Try a CVS snapshot (PHP 4.4): http://bugs.php.net/fix.php?id=37005&r=trysnapshot44
Try a CVS snapshot (PHP 5.1): http://bugs.php.net/fix.php?id=37005&r=trysnapshot51
Try a CVS snapshot (PHP 6.0): http://bugs.php.net/fix.php?id=37005&r=trysnapshot60
Fixed in CVS: http://bugs.php.net/fix.php?id=37005&r=fixedcvs
Fixed in release: http://bugs.php.net/fix.php?id=37005&r=alreadyfixed
Need backtrace: http://bugs.php.net/fix.php?id=37005&r=needtrace
Need Reproduce Script: http://bugs.php.net/fix.php?id=37005&r=needscript
Try newer version: http://bugs.php.net/fix.php?id=37005&r=oldversion
Not developer issue: http://bugs.php.net/fix.php?id=37005&r=support
Expected behavior: http://bugs.php.net/fix.php?id=37005&r=notwrong
Not enough info: http://bugs.php.net/fix.php?id=37005&r=notenoughinfo
Submitted twice: http://bugs.php.net/fix.php?id=37005&r=submittedtwice
register_globals: http://bugs.php.net/fix.php?id=37005&r=globals
PHP 3 support discontinued: http://bugs.php.net/fix.php?id=37005&r=php3
Daylight Savings: http://bugs.php.net/fix.php?id=37005&r=dst
IIS Stability: http://bugs.php.net/fix.php?id=37005&r=isapi
Install GNU Sed: http://bugs.php.net/fix.php?id=37005&r=gnused
Floating point limitations: http://bugs.php.net/fix.php?id=37005&r=float
No Zend Extensions: http://bugs.php.net/fix.php?id=37005&r=nozend
MySQL Configuration Error: http://bugs.php.net/fix.php?id=37005&r=mysqlcfg