#45441 [Opn->Ver]: count_chars() crashes if both arguments are the same reference
| From: | jani@php.net | Date: | Fri, 11 Jul 2008 15:44:27 +0000 |
| Subject: | #45441 [Opn->Ver]: count_chars() crashes if both arguments are the same reference | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-126489@lists.php.net to get a copy of this message | ||
ID: 45441
Updated by: jani@php.net
Reported By: victor dot stinner at haypocalc dot com
-Status: Open
+Status: Verified
Bug Type: Reproducible crash
-Operating System: Linux (Ubuntu Gutsy)
+Operating System: *
PHP Version: 5.2CVS-2008-07-06 (snap)
Previous Comments:
------------------------------------------------------------------------
[2008-07-06 23:30:21] victor dot stinner at haypocalc dot com
Description:
------------
count_chars() function converts the second argument ($mode) using
convert_to_long_ex(). If $input and $mode are both a reference to
the same variable, PHP crashs with a segfault.
Reproduce code:
---------------
<?php
$text = 'Hello World!';
$n = count_chars(&$text, &$text);
print_r($n);
?>
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/?id=45441&edit=1