Bug#783099: php5: Fileinfo on specific file causes spurious OOM and/or segfault

2015-04-24 Thread Christoph Biedl
Henri Salo wrote... > I reported this issue to Debian BTS to notify package maintainers and in the > long run trying to get security issues fixed. Maintainers are not always > following security issues in upstream and so on (not saying this about PHP). I This is appreciated but a short report abo

Bug#783099: php5: Fileinfo on specific file causes spurious OOM and/or segfault

2015-04-23 Thread Henri Salo
I reported this issue to Debian BTS to notify package maintainers and in the long run trying to get security issues fixed. Maintainers are not always following security issues in upstream and so on (not saying this about PHP). I verified that the segfault condition occurred and did not do more deta

Processed: Re: Bug#783099: php5: Fileinfo on specific file causes spurious OOM and/or segfault

2015-04-23 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > tags 783099 -unreproducible Bug #783099 [src:php5] php5: Fileinfo on specific file causes spurious OOM and/or segfault Bug #783107 [src:php5] php5: Fileinfo on specific file causes spurious OOM and/or segfault Removed tag(s) unreproducible. Remo

Bug#783099: php5: Fileinfo on specific file causes spurious OOM and/or segfault

2015-04-23 Thread Christoph Biedl
tags 783099 unreproducible thanks Henri Salo wrote... > When calling finfo::file() or finfo::buffer() with a crafted string, PHP will > crash by either segfaulting or trying to allocate an large amount of memory > (4GiB). (...) > > https://git.php.net/?p=php-src.git;a=commitdiff;h=f938112c495b

Processed: Re: Bug#783099: php5: Fileinfo on specific file causes spurious OOM and/or segfault

2015-04-23 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > tags 783099 unreproducible Bug #783099 [src:php5] php5: Fileinfo on specific file causes spurious OOM and/or segfault Bug #783107 [src:php5] php5: Fileinfo on specific file causes spurious OOM and/or segfault Added tag(s) unreproducible. Added t

Bug#783099: php5: Fileinfo on specific file causes spurious OOM and/or segfault

2015-04-22 Thread Henri Salo
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Source: php5 Version: 5.6.7+dfsg-1 Severity: grave Tags: security, upstream, fixed-upstream Hi, the following vulnerability was published for PHP5, """ When calling finfo::file() or finfo::buffer() with a crafted string, PHP will crash by either seg