#43201 [Opn->Asn]: Crash on using unitialized vals and __get/__set
| From: | jani@php.net | Date: | Fri, 09 Nov 2007 00:09:37 +0000 |
| Subject: | #43201 [Opn->Asn]: Crash on using unitialized vals and __get/__set | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-119376@lists.php.net to get a copy of this message | ||
ID: 43201
Updated by: jani@php.net
Reported By: stas at zend dot com
-Status: Open
+Status: Assigned
Bug Type: Scripting Engine problem
Operating System: *
PHP Version: 5.2CVS-2007-11-05 (CVS)
Assigned To: dmitry
Previous Comments:
------------------------------------------------------------------------
[2007-11-05 18:20:40] stas@php.net
Shorter version:
<?php
class Foo {
function __get($k) {
return null;
}
}
$c = new Foo();
$c->arr[0]["k"] = 1;
$c->arr[0]["k2"] = $undef;
for($cnt=0;$cnt<6;++$cnt) {
$c->arr[$cnt]["k2"] = chop($undef);
}
?>
------------------------------------------------------------------------
[2007-11-05 18:15:07] stas at zend dot com
Description:
------------
Code modifying the result of __get (erroneously) and using undefined
variables crashes, apparently because of unitialized_zval being freed.
Reproduce code:
---------------
<?php
class Foo {
function __get($k) {
return null;
}
function __set($k, $v) {
$this->$k = $v;
}
}
$c = new Foo();
$c->arr[0]["k"] = 1;
$c->arr[0]["k2"] = $ref;
for($cnt=0;$cnt<6;$cnt++) {
$ref = chop($undef);
$c->arr[$cnt]["k2"] = $ref;
}
?>
Expected result:
----------------
No crash :)
Actual result:
--------------
On windows - crash
On Unix debug -
php5/Zend/zend_hash.c(517) : ht=0xa533520 is being destroyed
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/?id=43201&edit=1