Bug #17724: php4/imap functions causing apache cores at random

From: Date: Wed, 12 Jun 2002 10:13:16 +0000
Subject: Bug #17724: php4/imap functions causing apache cores at random
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-10221@lists.php.net to get a copy of this message
From: si@darkness.nu Operating system: IRIX 6.5.16F / IP25 PHP version: 4.2.1 PHP Bug Type: Reproducible crash Bug description: php4/imap functions causing apache cores at random Appears to be possibly memory corruption in imap functions under php4.2.1? Compiled using imap-2001a. This GDB was configured as "mips-sgi-irix6.5"... Core was generated by `httpd'. Program terminated with signal 11, Segmentation fault. Reading symbols from /usr/lib32/libcrypt.so...done. Reading symbols from /usr/lib32/libm.so...done. Reading symbols from /usr/lib32/libdl.so...done. Reading symbols from /usr/lib32/libsocket.so...done. Reading symbols from /usr/freeware/lib32/libssl.so...done. Reading symbols from /usr/freeware/lib32/libcrypto.so...done. Reading symbols from /usr/lib32/libc.so.1...done. #0 0x1021be74 in imap_valid (name=0x105e9570 "{localhost:143}") at imap4r1.c:113 113 { (gdb) bt #0 0x1021be74 in imap_valid (name=0x105e9570 "{localhost:143}") at imap4r1.c:113 #1 0x1021c4c8 in imap_list_work (stream=0x105eaae8, cmd=0x102eedc0 "LSUB", ref=0x105e9570 "{localhost:143}", pat=0x105614c0 "*", contents=0x0) at imap4r1.c:280 #2 0x1021c328 in imap_lsub (stream=0x105eaae8, ref=0x105e9570 "{localhost:143}", pat=0x105614c0 "*") at imap4r1.c:248 #3 0x101f5458 in mail_lsub (stream=0x105eaae8, ref=0x105e9570 "{localhost:143}", pat=0x105614c0 "*") at mail.c:754 #4 0x10148400 in zif_imap_lsub (ht=3, return_value=0x105e92c8, this_ptr=0x105e9570, return_value_used=274076864) at php_imap.c:1706 #5 0x100e2eb8 in execute (op_array=0x105557c8) at zend_execute.c:1598 #6 0x100e3100 in execute (op_array=0x10457c90) at zend_execute.c:1638 #7 0x100e3100 in execute (op_array=0x105952b0) at zend_execute.c:1638 #8 0x100e3100 in execute (op_array=0x105d7d50) at zend_execute.c:1638 #9 0x100e5424 in execute (op_array=0x1052b3e0) at zend_execute.c:2141 #10 0x100e5424 in execute (op_array=0x104d5c80) at zend_execute.c:2141 #11 0x100700a0 in zend_execute_scripts (type=8, retval=0x0, file_count=3) at zend.c:810 #12 0x10064e44 in php_execute_script (primary_file=0x7fff2970) at main.c:1381 #13 0x100dcec4 in apache_php_module_main (r=0x7fff2970, display_source_mode=2147428744) at sapi_apache.c:90 #14 0x10061370 in php_restore_umask () This GDB was configured as "mips-sgi-irix6.5"... Core was generated by `httpd'. Program terminated with signal 11, Segmentation fault. Reading symbols from /usr/lib32/libcrypt.so...done. Reading symbols from /usr/lib32/libm.so...done. Reading symbols from /usr/lib32/libdl.so...done. Reading symbols from /usr/lib32/libsocket.so...done. Reading symbols from /usr/freeware/lib32/libssl.so...done. Reading symbols from /usr/freeware/lib32/libcrypto.so...done. Reading symbols from /usr/lib32/libc.so.1...done. #0 0x1021c284 in imap_list (stream=0x104f74d8, ref=0x1021c280 "'½ÿàÿ¿", pat=0x104e2507 "/%") at imap4r1.c:232 232 { (gdb) bt #0 0x1021c284 in imap_list (stream=0x104f74d8, ref=0x1021c280 "'½ÿàÿ¿", pat=0x104e2507 "/%") at imap4r1.c:232 #1 0x101f5228 in mail_list (stream=0x104f74d8, ref=0x104b5500 "{mail.darkness.nu:143}", pat=0x104e2500 "BasiliX/%") at mail.c:721 #2 0x10146af4 in zif_imap_list_full (ht=3, return_value=0x104e24b0, this_ptr=0x104e2500, return_value_used=273556743) at php_imap.c:1420 #3 0x100e2eb8 in execute (op_array=0x1043b5d0) at zend_execute.c:1598 #4 0x100e3100 in execute (op_array=0x1041c530) at zend_execute.c:1638 #5 0x100e3100 in execute (op_array=0x104aedd0) at zend_execute.c:1638 #6 0x100e3100 in execute (op_array=0x104a02b0) at zend_execute.c:1638 #7 0x100e5424 in execute (op_array=0x10468f78) at zend_execute.c:2141 #8 0x100700a0 in zend_execute_scripts (type=8, retval=0x0, file_count=3) at zend.c:810 #9 0x10064e44 in php_execute_script (primary_file=0x7fff2930) at main.c:1381 #10 0x100dcec4 in apache_php_module_main (r=0x7fff2930, display_source_mode=2147428680) at sapi_apache.c:90 #11 0x10061370 in php_restore_umask () -- Edit bug report at http://bugs.php.net/?id=17724&edit=1 -- Fixed in CVS: http://bugs.php.net/fix.php?id=17724&r=fixedcvs Fixed in release: http://bugs.php.net/fix.php?id=17724&r=alreadyfixed Need backtrace: http://bugs.php.net/fix.php?id=17724&r=needtrace Try newer version: http://bugs.php.net/fix.php?id=17724&r=oldversion Not developer issue: http://bugs.php.net/fix.php?id=17724&r=support Expected behavior: http://bugs.php.net/fix.php?id=17724&r=notwrong Not enough info: http://bugs.php.net/fix.php?id=17724&r=notenoughinfo Submitted twice: http://bugs.php.net/fix.php?id=17724&r=submittedtwice register_globals: http://bugs.php.net/fix.php?id=17724&r=globals

« previous php.bugs (#10221) next »