Bug #71197 [Asn]: 2 more segfaults in PHP's range() function

[email protected]
Newsgroups php.bugs
Message-ID <[email protected]>
Edit report at https://bugs.php.net/bug.php?id=71197&edit=1

 ID:                 71197
 Updated by:         [email protected]
 Reported by:        [email protected]
 Summary:            2 more segfaults in PHP's range() function
 Status:             Assigned
 Type:               Bug
 Package:            Reproducible crash
 Operating System:   Mac OS X Yosemite
 PHP Version:        7.0.1
 Assigned To:        tpunt
 Block user comment: N
 Private report:     N

 New Comment:

PR: https://github.com/php/php-src/pull/1690


Previous Comments:
------------------------------------------------------------------------
[2015-12-22 15:58:07] [email protected]

Description:
------------
The segfaults are caused by precision loss of large longs being converted to doubles when the `step` parameter is a double. The for loops continue infinitely since the `step` being added/subtracted upon each iteration is too small to be represented accurately as a double.

The attached patch adds another condition to each of the for loops by ensuring that the number of iterations in the loop are less than the size of the range (`__calc_size`). This prevents both loops from continuing until segfaulting, however doesn't give an accurate result (due to `__calc_size` being incorrect because of aforementioned precision loss).

Test script:
---------------
var_dump(count(range(PHP_INT_MIN, PHP_INT_MIN + 513, .01)));
var_dump(count(range(PHP_INT_MIN + 513, PHP_INT_MIN, .01)));

Expected result:
----------------
// A completely correct output would be:
int(51400)
int(51400)

Actual result:
--------------
Segmentation fault: 11
Segmentation fault: 11


------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=71197&edit=1
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.