Bug #18422 Updated: emalloc() call crashes Apache (backtrace provided)
| From: | sniper@php.net | Date: | Thu, 18 Jul 2002 21:52:48 +0000 |
| Subject: | Bug #18422 Updated: emalloc() call crashes Apache (backtrace provided) | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-14568@lists.php.net to get a copy of this message | ||
ID: 18422
Updated by: sniper@php.net
Reported By: acs@hourglassone.com
-Status: Open
+Status: Feedback
Bug Type: Reproducible crash
Operating System: Redhat Linux 7.2
PHP Version: 4.2.1
New Comment:
Firs try this snapshot:
http://snaps.php.net/php4-latest.tar.gz
And if it does not work, give a short, complete and standalone script
which can easily be used to reproduce this. As it seems the crash
happens in split(), come up with such script that does NOT include
anything but it and the data that crashes it.
Previous Comments:
------------------------------------------------------------------------
[2002-07-18 17:06:15] acs@hourglassone.com
Looks like you're correct.. I added a trim() around the second
paramater of split() and it seems to take care of it.
It would seem that there's no checking done on the size parameter in
php_split before calling add_next_index_stringl for the last value.
line number is ext/standard/reg.c:574 in php4.2.2dev
Snippet of code (offending line marked by >>>> <<<<), $sHeader is
returned by curl_exec):
class HeaderObj {
function HeaderObj($sHeader) {
$this->header = $sHeader;
$aHeaders = Array();
>>>>
$aLines = split("\n",$sHeader);
<<<<
foreach($aLines as $sLine) {
$temp = split(":",trim($sLine));
$aHeaders[$temp[0]] = (isset($temp[1])) ? trim($temp[1]) : "";
if ($temp[0] == "Content-Type") {
if (!isset($temp[1])) {
$aHeaders[$temp[0]] = trim("text/html");
}
}
}
if (!isset($aHeaders['Content-Type'])) {
$aHeaders['Content-Type'] = "text/html";
}
$this->headers = $aHeaders;
$this->headers['string'] = $sHeader;
reset($this->headers);
}
}
---
If I put it in a trim(), with --enable-debug, I get this warning:
<b>Warning</b>: String is not zero-terminated (HTTP/1.1 200 OK
Date: Thu, 18 Jul 2002 20:58:13 GMT
Server: Apache/1.3.23 (Unix)
Last-Modified: Fri, 28 Jun 2002 23:00:30 GMT
ETag: "736-3d1cea8e"
Accept-Ranges: bytes
Content-Length: 1846
Content-Type: application/x-javascript
Toolbar=search; siteinfopopup=siteinfo; relatedlinkspopup=relatedlinks;
twym=webyoumade; searchMethod=Yahoo; twym_disabled=false;
ALXSID=ccd89a2e038361a7cb25c7f27130ed86;
twym65=D4ABCAC7DEF19AA7979F60CED1A3%2521D7AED1C9EBED9CA59DA7A6DE9099A2E7%2521DB6C8FD3EBE1%2521C5ACD5C5E5DBAF9CA7AB9399C4A5ABA8A89D%2521D1B2D4D5E5A89CA2A1;
aid=iKy4Z0eeh000NE
Host: client.alexa.com:2222
Pragma: no-cache
Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, */*
Referer: http://client.alexa.com/speed_test/index.html
Accept-Language: en-us
@) (source: zend_execute_API.c:274) in <b>Unknown</b> on line
<b>0</b><br />
------------------------------------------------------------------------
[2002-07-18 16:31:05] derick@php.net
It crashes on a split function, can you try to shorten your script to
narrow the search for us?
Derick
------------------------------------------------------------------------
[2002-07-18 16:24:04] acs@hourglassone.com
I have a script that proxies a request through Curl to an instance of
apache running on the same machine with a different port number. This
script worked great until I installed 4.2.1.
Error logs show:
FATAL: emalloc(): Unable to allocate -491 bytes
I'm not entirely sure where the error is being caused. The script in
question is using curl, xpath, and mysql.
Running HTTPD with -X under gdb yields this backtrace:
#0 0x4010da01 in __kill () from /lib/i686/libc.so.6
#1 0x404a9a51 in _emalloc (size=4294966827, __zend_filename=0x405aaa60
"zend_API.c", __zend_lineno=845, __zend_orig_filename=0x0,
__zend_orig_lineno=0) at zend_alloc.c:173
#2 0x404aa17d in _estrndup (s=0x814a3a3 "", length=4294966826,
__zend_filename=0x405aaa60 "zend_API.c", __zend_lineno=845,
__zend_orig_filename=0x0, __zend_orig_lineno=0) at
zend_alloc.c:340
#3 0x404c949a in add_next_index_stringl (arg=0x814bde4, str=0x814a3a3
"", length=4294966826, duplicate=1) at zend_API.c:845
#4 0x40555489 in php_split (ht=2, return_value=0x814bde4,
this_ptr=0x0, return_value_used=1, icase=0) at reg.c:594
#5 0x405554b0 in zif_split (ht=2, return_value=0x814bde4,
this_ptr=0x0, return_value_used=1) at reg.c:604
#6 0x404b6455 in execute (op_array=0x812ac8c) at
./zend_execute.c:1598
#7 0x404b6667 in execute (op_array=0x8134b94) at
./zend_execute.c:1638
#8 0x404b6667 in execute (op_array=0x8138674) at
./zend_execute.c:1638
#9 0x404b6667 in execute (op_array=0x8121de4) at
./zend_execute.c:1638
#10 0x404c70a8 in zend_execute_scripts (type=8, retval=0x0,
file_count=3) at zend.c:810
#11 0x404d98ca in php_execute_script (primary_file=0xbffff5b0) at
main.c:1381
#12 0x404d4316 in apache_php_module_main (r=0x8115cec,
display_source_mode=0) at sapi_apache.c:90
#13 0x404d5184 in send_php (r=0x8115cec, display_source_mode=0,
filename=0x81179e4 "/www/redir.php") at mod_php4.c:575
#14 0x404d51f1 in send_parsed_php (r=0x8115cec) at mod_php4.c:590
#15 0x08054757 in ap_invoke_handler ()
#16 0x080695af in process_request_internal ()
#17 0x08069610 in ap_process_request ()
#18 0x08060799 in child_main ()
#19 0x08060968 in make_child ()
#20 0x08060adc in startup_children ()
#21 0x08061154 in standalone_main ()
#22 0x080619c3 in main ()
#23 0x400fb507 in __libc_start_main (main=0x8061610 <main>, argc=3,
ubp_av=0xbffff9e4, init=0x804ebd4 <_init>, fini=0x8080c40 <_fini>,
rtld_fini=0x4000dc14 <_dl_fini>, stack_end=0xbffff9dc) at
../sysdeps/generic/libc-start.c:129
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/?id=18422&edit=1