Bug #15829 Updated: using nonexistingn back reference in regex crashes PHP

From: Date: Mon, 17 Jun 2002 21:19:02 +0000
Subject: Bug #15829 Updated: using nonexistingn back reference in regex crashes PHP
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-10944@lists.php.net to get a copy of this message
ID: 15829 Updated by: msopacua@idg.nl Reported By: sander@php.net Status: Open Bug Type: Reproducible crash Operating System: Debian (Sid) Linux PHP Version: 4.0CVS-2002-03-0 New Comment: As referred from dupe 17786. I can't get a good backtrace, but I'm sure I have a debug build, since phpinfo() says so and I have several leak reports my error log, when running chora 1.1. I also was able to reproduce it in apache, but the debug info is exactly the same. Even forcing CFLAGS=-g doesn't help. Previous Comments: ------------------------------------------------------------------------ [2002-04-12 15:42:10] cynic@php.net I'm afraid this will get through terribly mangled... roman@roman ~/install/php4-latest > cat ~/tmp/ereg.test 141:1 <? $foo = "abc123"; echo ereg_replace("123", 'def\1ghi', $foo); echo "\n"; ?> roman@roman ~/install/php4-latest > ./php -c /dev/null -qC ~/tmp/ereg.test 142:0 zsh: 84733 segmentation fault (core dumped) ./php -c /dev/null -qC ~/tmp/ereg.test roman@roman ~/install/php4-latest > gdb ./php ./php.core 144:0 GNU gdb 4.18 Copyright 1998 Free Software Foundation, Inc. GDB is free software, covered by the GNU General Public License, and you are welcome to change it and/or distribute copies of it under certain conditions. Type "show copying" to see the conditions. There is absolutely no warranty for GDB. Type "show warranty" for details. This GDB was configured as "i386-unknown-freebsd"... Core was generated by `php'. Program terminated with signal 11, Segmentation fault. Reading symbols from /usr/lib/libhistory.so.4...done. Reading symbols from /usr/lib/libreadline.so.4...done. Reading symbols from /usr/lib/libncurses.so.5...done. Reading symbols from /usr/local/lib/libgiconv.so.2...done. Reading symbols from /usr/local/lib/libintl.so.1...done. Reading symbols from /usr/lib/libssl.so.2...done. Reading symbols from /usr/lib/libcrypto.so.2...done. Reading symbols from /usr/local/lib/libcurl.so.2...done. Reading symbols from /usr/lib/libbz2.so.1...done. Reading symbols from /usr/lib/libz.so.2...done. Reading symbols from /usr/lib/libcrypt.so.2...done. Reading symbols from /usr/lib/libm.so.2...done. Reading symbols from /usr/lib/libc.so.4...done. Reading symbols from /usr/libexec/ld-elf.so.1...done. #0 0x284c7c82 in memcpy () from /usr/lib/libc.so.4 (gdb) bt #0 0x284c7c82 in memcpy () from /usr/lib/libc.so.4 #1 0xd570337c in ?? () #2 0x80cd88a in php_ereg_replace (ht=3, return_value=0x820b864, this_ptr=0x0, return_value_used=1, icase=0) at /home/roman/install/php4-latest/ext/standard/reg.c:476 #3 0x80cd9d8 in zif_ereg_replace (ht=3, return_value=0x820b864, this_ptr=0x0, return_value_used=1) at /home/roman/install/php4-latest/ext/standard/reg.c:494 #4 0x815633a in execute (op_array=0x820c724) at /home/roman/install/php4-latest/Zend/zend_execute.c:1598 #5 0x8145f6d in zend_execute_scripts (type=8, retval=0x0, file_count=3) at /home/roman/install/php4-latest/Zend/zend.c:810 #6 0x8118b69 in php_execute_script (primary_file=0xbfbffa78) at /home/roman/install/php4-latest/main/main.c:1405 #7 0x815baf4 in main (argc=5, argv=0xbfbffaf4) at /home/roman/install/php4-latest/sapi/cgi/cgi_main.c:1020 #8 0x8064819 in _start () (gdb) ------------------------------------------------------------------------ [2002-04-12 15:22:41] sander@php.net I reported this BEFORE 4.2.0 was branched. I can't reproduce it anymore with todya's HEAD. ------------------------------------------------------------------------ [2002-04-12 15:09:12] cynic@php.net which branch? I'm seeing this on HEAD. I've just started a new build, will post backtrace within 20 minutes. ------------------------------------------------------------------------ [2002-04-12 14:57:17] sniper@php.net Doesn't crash here either.. ------------------------------------------------------------------------ [2002-04-12 12:38:02] cynic@php.net I have it segfaulting there as well. FreeBSD roman.mobil.cz 4.4-STABLE FreeBSD 4.4-STABLE #0: Wed Dec 26 12:45:18 CET 2001 root@roman.mobil.cz:/usr/obj/usr/src/sys/CRUDPUPPY_3 i386 './configure' \ '--disable-shared' \ '--disable-session' \ '--enable-debug' \ '--enable-inline-optimization' \ '--enable-dio' \ '--enable-ftp' \ '--enable-pcntl' \ '--enable-shmop' \ '--enable-sysvsem' \ '--enable-sysvshm' \ '--enable-sockets' \ '--enable-tokenizer' \ '--without-mysql' \ '--with-openssl' \ '--with-zlib' \ '--with-bz2' \ '--with-curl' \ '--with-gettext' \ '--with-iconv' \ '--with-ncurses' \ '--with-readline' \ "$@" I don't have a backtrace yet. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at http://bugs.php.net/15829 -- Edit this bug report at http://bugs.php.net/?id=15829&edit=1

« previous php.bugs (#10944) next »