Bug #18422 Updated: emalloc() call crashes Apache (backtrace provided)

From: Date: Thu, 18 Jul 2002 21:06:18 +0000
Subject: Bug #18422 Updated: emalloc() call crashes Apache (backtrace provided)
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-14561@lists.php.net to get a copy of this message
ID: 18422 Updated by: acs@hourglassone.com Reported By: acs@hourglassone.com -Status: Feedback +Status: Open Bug Type: Reproducible crash Operating System: Redhat Linux 7.2 PHP Version: 4.2.1 New Comment: Looks like you're correct.. I added a trim() around the second paramater of split() and it seems to take care of it. It would seem that there's no checking done on the size parameter in php_split before calling add_next_index_stringl for the last value. line number is ext/standard/reg.c:574 in php4.2.2dev Snippet of code (offending line marked by >>>> <<<<), $sHeader is returned by curl_exec): class HeaderObj { function HeaderObj($sHeader) { $this->header = $sHeader; $aHeaders = Array(); >>>> $aLines = split("\n",$sHeader); <<<< foreach($aLines as $sLine) { $temp = split(":",trim($sLine)); $aHeaders[$temp[0]] = (isset($temp[1])) ? trim($temp[1]) : ""; if ($temp[0] == "Content-Type") { if (!isset($temp[1])) { $aHeaders[$temp[0]] = trim("text/html"); } } } if (!isset($aHeaders['Content-Type'])) { $aHeaders['Content-Type'] = "text/html"; } $this->headers = $aHeaders; $this->headers['string'] = $sHeader; reset($this->headers); } } --- If I put it in a trim(), with --enable-debug, I get this warning: <b>Warning</b>: String is not zero-terminated (HTTP/1.1 200 OK Date: Thu, 18 Jul 2002 20:58:13 GMT Server: Apache/1.3.23 (Unix) Last-Modified: Fri, 28 Jun 2002 23:00:30 GMT ETag: "736-3d1cea8e" Accept-Ranges: bytes Content-Length: 1846 Content-Type: application/x-javascript Toolbar=search; siteinfopopup=siteinfo; relatedlinkspopup=relatedlinks; twym=webyoumade; searchMethod=Yahoo; twym_disabled=false; ALXSID=ccd89a2e038361a7cb25c7f27130ed86; twym65=D4ABCAC7DEF19AA7979F60CED1A3%2521D7AED1C9EBED9CA59DA7A6DE9099A2E7%2521DB6C8FD3EBE1%2521C5ACD5C5E5DBAF9CA7AB9399C4A5ABA8A89D%2521D1B2D4D5E5A89CA2A1; aid=iKy4Z0eeh000NE Host: client.alexa.com:2222 Pragma: no-cache Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, */* Referer: http://client.alexa.com/speed_test/index.html Accept-Language: en-us @) (source: zend_execute_API.c:274) in <b>Unknown</b> on line <b>0</b><br /> Previous Comments: ------------------------------------------------------------------------ [2002-07-18 16:31:05] derick@php.net It crashes on a split function, can you try to shorten your script to narrow the search for us? Derick ------------------------------------------------------------------------ [2002-07-18 16:24:04] acs@hourglassone.com I have a script that proxies a request through Curl to an instance of apache running on the same machine with a different port number. This script worked great until I installed 4.2.1. Error logs show: FATAL: emalloc(): Unable to allocate -491 bytes I'm not entirely sure where the error is being caused. The script in question is using curl, xpath, and mysql. Running HTTPD with -X under gdb yields this backtrace: #0 0x4010da01 in __kill () from /lib/i686/libc.so.6 #1 0x404a9a51 in _emalloc (size=4294966827, __zend_filename=0x405aaa60 "zend_API.c", __zend_lineno=845, __zend_orig_filename=0x0, __zend_orig_lineno=0) at zend_alloc.c:173 #2 0x404aa17d in _estrndup (s=0x814a3a3 "", length=4294966826, __zend_filename=0x405aaa60 "zend_API.c", __zend_lineno=845, __zend_orig_filename=0x0, __zend_orig_lineno=0) at zend_alloc.c:340 #3 0x404c949a in add_next_index_stringl (arg=0x814bde4, str=0x814a3a3 "", length=4294966826, duplicate=1) at zend_API.c:845 #4 0x40555489 in php_split (ht=2, return_value=0x814bde4, this_ptr=0x0, return_value_used=1, icase=0) at reg.c:594 #5 0x405554b0 in zif_split (ht=2, return_value=0x814bde4, this_ptr=0x0, return_value_used=1) at reg.c:604 #6 0x404b6455 in execute (op_array=0x812ac8c) at ./zend_execute.c:1598 #7 0x404b6667 in execute (op_array=0x8134b94) at ./zend_execute.c:1638 #8 0x404b6667 in execute (op_array=0x8138674) at ./zend_execute.c:1638 #9 0x404b6667 in execute (op_array=0x8121de4) at ./zend_execute.c:1638 #10 0x404c70a8 in zend_execute_scripts (type=8, retval=0x0, file_count=3) at zend.c:810 #11 0x404d98ca in php_execute_script (primary_file=0xbffff5b0) at main.c:1381 #12 0x404d4316 in apache_php_module_main (r=0x8115cec, display_source_mode=0) at sapi_apache.c:90 #13 0x404d5184 in send_php (r=0x8115cec, display_source_mode=0, filename=0x81179e4 "/www/redir.php") at mod_php4.c:575 #14 0x404d51f1 in send_parsed_php (r=0x8115cec) at mod_php4.c:590 #15 0x08054757 in ap_invoke_handler () #16 0x080695af in process_request_internal () #17 0x08069610 in ap_process_request () #18 0x08060799 in child_main () #19 0x08060968 in make_child () #20 0x08060adc in startup_children () #21 0x08061154 in standalone_main () #22 0x080619c3 in main () #23 0x400fb507 in __libc_start_main (main=0x8061610 <main>, argc=3, ubp_av=0xbffff9e4, init=0x804ebd4 <_init>, fini=0x8080c40 <_fini>, rtld_fini=0x4000dc14 <_dl_fini>, stack_end=0xbffff9dc) at ../sysdeps/generic/libc-start.c:129 ------------------------------------------------------------------------ -- Edit this bug report at http://bugs.php.net/?id=18422&edit=1

« previous php.bugs (#14561) next »