Comment 3 for bug 351730

Revision history for this message
Kees Cook (kees) wrote :

#0 0x00007f92c332d2a3 in memcpy () from /lib/libc.so.6
#1 0x00000000006551b8 in _estrndup (s=0x7fffce3e2f30 "0Y�\001",
    length=4294967295) at /usr/include/bits/string3.h:52
#2 0x0000000000674fbb in add_next_index_stringl (arg=0x1c25a60,
    str=0x7fffce3e2f30 "0Y�\001", length=4294967295, duplicate=1)
    at /build/buildd/php5-5.2.6.dfsg.1/Zend/zend_API.c:1213
#3 0x0000000000466fdd in add_assoc_name_entry (val=0x6f1f9f,
    key=0x101b63c40 <Address 0x101b63c40 out of bounds>, name=0x1b10e20,
    shortname=32767)
    at /build/buildd/php5-5.2.6.dfsg.1/ext/openssl/openssl.c:307
#4 0x000000000046720d in zif_openssl_x509_parse (ht=29541608,
    return_value=0x6e69207372656b61, return_value_ptr=0xffffbfff,
    this_ptr=0x3fbc, return_value_used=1048576)
    at /build/buildd/php5-5.2.6.dfsg.1/ext/openssl/openssl.c:1024
#5 0x00000000006a8b6d in zend_do_fcall_common_helper_SPEC (
    execute_data=0x7fffce3e32a0)
    at /build/buildd/php5-5.2.6.dfsg.1/Zend/zend_vm_execute.h:200
#6 0x00000000006940a4 in execute (op_array=0x1c24a10)
    at /build/buildd/php5-5.2.6.dfsg.1/Zend/zend_vm_execute.h:92
#7 0x000000000066fd68 in zend_execute_scripts (type=32767, retval=0x0,
    file_count=-834784296) at /build/buildd/php5-5.2.6.dfsg.1/Zend/zend.c:1215
#8 0x0000000000629ef2 in php_execute_script (primary_file=Cannot access memory at address 0x8000ce3e2330
)
    at /build/buildd/php5-5.2.6.dfsg.1/main/main.c:2028
#9 0x00000000006f020b in main (argc=-834774360, argv=0x7f92c32b9210)
    at /build/buildd/php5-5.2.6.dfsg.1/sapi/cli/php_cli.c:1148