#41101 [Opn->Csd]: segfault when setcookie deletes session cookie with path information

From: Date: Mon, 16 Apr 2007 12:49:17 +0000
Subject: #41101 [Opn->Csd]: segfault when setcookie deletes session cookie with path information
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-111538@lists.php.net to get a copy of this message
ID: 41101 Updated by: tony2001@php.net Reported By: tokul at users dot sourceforge dot net -Status: Open +Status: Closed Bug Type: Reproducible crash Operating System: Linux Debian Etch PHP Version: 6CVS-2007-04-16 (snap) New Comment: This bug has been fixed in CVS. Snapshots of the sources are packaged every three hours; this change will be in the next snapshot. You can grab the snapshot at http://snaps.php.net/. Thank you for the report, and for helping us make PHP better. Previous Comments: ------------------------------------------------------------------------ [2007-04-16 12:02:56] tokul at users dot sourceforge dot net Description: ------------ PHP6-200704160630 snapshot compiled with --prefix, --with-apxs2 and --config-path options. Apache 2.2.4. If setcookie() tries to delete session cookie, it causes 'zend_mm_heap corrupted' error or segfault in apache logs. I have found other bug reports about 'zend_mm_heap corrupted' error, but they are closed in February or March. I can reproduce crash in current PHP6 snapshot. Code does not crash if fourth argument is set to '/'. Script is called from /path/ directory. Reproduce code: --------------- session_start(); setcookie(session_name(), '', 0, '/path'); die('test'); Expected result: ---------------- test Actual result: -------------- Browser tries to download php script and I get 'zend_mm_heap corrupted' message in error_log. Real code generated 'child pid #### exit signal Segmentation fault (11)'. I wanted to simplify code and got zend_mm_heap error instead of segfault. ------------------------------------------------------------------------ -- Edit this bug report at http://bugs.php.net/?id=41101&edit=1

« previous php.bugs (#111538) next »