#45441 [Ver->Fbk]: count_chars() crashes if both arguments are the same reference

From: Date: Sat, 02 Aug 2008 22:35:50 +0000
Subject: #45441 [Ver->Fbk]: count_chars() crashes if both arguments are the same reference
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-127521@lists.php.net to get a copy of this message
ID: 45441 Updated by: lbarnaud@php.net Reported By: victor dot stinner at haypocalc dot com -Status: Verified +Status: Feedback Bug Type: Reproducible crash Operating System: * PHP Version: 5.2CVS-2008-07-06 (snap) New Comment: Please try using this CVS snapshot: http://snaps.php.net/php5.3-latest.tar.gz For Windows (zip): http://snaps.php.net/win32/php5.3-win32-latest.zip For Windows (installer): http://snaps.php.net/win32/php5.3-win32-installer-latest.msi Previous Comments: ------------------------------------------------------------------------ [2008-07-06 23:30:21] victor dot stinner at haypocalc dot com Description: ------------ count_chars() function converts the second argument ($mode) using convert_to_long_ex(). If $input and $mode are both a reference to the same variable, PHP crashs with a segfault. Reproduce code: --------------- <?php $text = 'Hello World!'; $n = count_chars(&$text, &$text); print_r($n); ?> ------------------------------------------------------------------------ -- Edit this bug report at http://bugs.php.net/?id=45441&edit=1

« previous php.bugs (#127521) next »