Bug #18422 Updated: emalloc() call crashes Apache (backtrace provided)
| From: | acs at hourglassone dot com | Date: | Thu, 18 Jul 2002 21:06:18 +0000 |
| Subject: | Bug #18422 Updated: emalloc() call crashes Apache (backtrace provided) | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-14561@lists.php.net to get a copy of this message | ||
ID: 18422
Updated by: acs@hourglassone.com
Reported By: acs@hourglassone.com
-Status: Feedback
+Status: Open
Bug Type: Reproducible crash
Operating System: Redhat Linux 7.2
PHP Version: 4.2.1
New Comment:
Looks like you're correct.. I added a trim() around the second
paramater of split() and it seems to take care of it.
It would seem that there's no checking done on the size parameter in
php_split before calling add_next_index_stringl for the last value.
line number is ext/standard/reg.c:574 in php4.2.2dev
Snippet of code (offending line marked by >>>> <<<<), $sHeader is
returned by curl_exec):
class HeaderObj {
function HeaderObj($sHeader) {
$this->header = $sHeader;
$aHeaders = Array();
>>>>
$aLines = split("\n",$sHeader);
<<<<
foreach($aLines as $sLine) {
$temp = split(":",trim($sLine));
$aHeaders[$temp[0]] = (isset($temp[1])) ? trim($temp[1]) : "";
if ($temp[0] == "Content-Type") {
if (!isset($temp[1])) {
$aHeaders[$temp[0]] = trim("text/html");
}
}
}
if (!isset($aHeaders['Content-Type'])) {
$aHeaders['Content-Type'] = "text/html";
}
$this->headers = $aHeaders;
$this->headers['string'] = $sHeader;
reset($this->headers);
}
}
---
If I put it in a trim(), with --enable-debug, I get this warning:
<b>Warning</b>: String is not zero-terminated (HTTP/1.1 200 OK
Date: Thu, 18 Jul 2002 20:58:13 GMT
Server: Apache/1.3.23 (Unix)
Last-Modified: Fri, 28 Jun 2002 23:00:30 GMT
ETag: "736-3d1cea8e"
Accept-Ranges: bytes
Content-Length: 1846
Content-Type: application/x-javascript
Toolbar=search; siteinfopopup=siteinfo; relatedlinkspopup=relatedlinks;
twym=webyoumade; searchMethod=Yahoo; twym_disabled=false;
ALXSID=ccd89a2e038361a7cb25c7f27130ed86;
twym65=D4ABCAC7DEF19AA7979F60CED1A3%2521D7AED1C9EBED9CA59DA7A6DE9099A2E7%2521DB6C8FD3EBE1%2521C5ACD5C5E5DBAF9CA7AB9399C4A5ABA8A89D%2521D1B2D4D5E5A89CA2A1;
aid=iKy4Z0eeh000NE
Host: client.alexa.com:2222
Pragma: no-cache
Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, */*
Referer: http://client.alexa.com/speed_test/index.html
Accept-Language: en-us
@) (source: zend_execute_API.c:274) in <b>Unknown</b> on line
<b>0</b><br />
Previous Comments:
------------------------------------------------------------------------
[2002-07-18 16:31:05] derick@php.net
It crashes on a split function, can you try to shorten your script to
narrow the search for us?
Derick
------------------------------------------------------------------------
[2002-07-18 16:24:04] acs@hourglassone.com
I have a script that proxies a request through Curl to an instance of
apache running on the same machine with a different port number. This
script worked great until I installed 4.2.1.
Error logs show:
FATAL: emalloc(): Unable to allocate -491 bytes
I'm not entirely sure where the error is being caused. The script in
question is using curl, xpath, and mysql.
Running HTTPD with -X under gdb yields this backtrace:
#0 0x4010da01 in __kill () from /lib/i686/libc.so.6
#1 0x404a9a51 in _emalloc (size=4294966827, __zend_filename=0x405aaa60
"zend_API.c", __zend_lineno=845, __zend_orig_filename=0x0,
__zend_orig_lineno=0) at zend_alloc.c:173
#2 0x404aa17d in _estrndup (s=0x814a3a3 "", length=4294966826,
__zend_filename=0x405aaa60 "zend_API.c", __zend_lineno=845,
__zend_orig_filename=0x0, __zend_orig_lineno=0) at
zend_alloc.c:340
#3 0x404c949a in add_next_index_stringl (arg=0x814bde4, str=0x814a3a3
"", length=4294966826, duplicate=1) at zend_API.c:845
#4 0x40555489 in php_split (ht=2, return_value=0x814bde4,
this_ptr=0x0, return_value_used=1, icase=0) at reg.c:594
#5 0x405554b0 in zif_split (ht=2, return_value=0x814bde4,
this_ptr=0x0, return_value_used=1) at reg.c:604
#6 0x404b6455 in execute (op_array=0x812ac8c) at
./zend_execute.c:1598
#7 0x404b6667 in execute (op_array=0x8134b94) at
./zend_execute.c:1638
#8 0x404b6667 in execute (op_array=0x8138674) at
./zend_execute.c:1638
#9 0x404b6667 in execute (op_array=0x8121de4) at
./zend_execute.c:1638
#10 0x404c70a8 in zend_execute_scripts (type=8, retval=0x0,
file_count=3) at zend.c:810
#11 0x404d98ca in php_execute_script (primary_file=0xbffff5b0) at
main.c:1381
#12 0x404d4316 in apache_php_module_main (r=0x8115cec,
display_source_mode=0) at sapi_apache.c:90
#13 0x404d5184 in send_php (r=0x8115cec, display_source_mode=0,
filename=0x81179e4 "/www/redir.php") at mod_php4.c:575
#14 0x404d51f1 in send_parsed_php (r=0x8115cec) at mod_php4.c:590
#15 0x08054757 in ap_invoke_handler ()
#16 0x080695af in process_request_internal ()
#17 0x08069610 in ap_process_request ()
#18 0x08060799 in child_main ()
#19 0x08060968 in make_child ()
#20 0x08060adc in startup_children ()
#21 0x08061154 in standalone_main ()
#22 0x080619c3 in main ()
#23 0x400fb507 in __libc_start_main (main=0x8061610 <main>, argc=3,
ubp_av=0xbffff9e4, init=0x804ebd4 <_init>, fini=0x8080c40 <_fini>,
rtld_fini=0x4000dc14 <_dl_fini>, stack_end=0xbffff9dc) at
../sysdeps/generic/libc-start.c:129
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/?id=18422&edit=1