Bug #18422 Updated: emalloc() call crashes Apache (backtrace provided)

From: Date: Thu, 18 Jul 2002 21:52:48 +0000
Subject: Bug #18422 Updated: emalloc() call crashes Apache (backtrace provided)
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-14568@lists.php.net to get a copy of this message
ID: 18422 Updated by: sniper@php.net Reported By: acs@hourglassone.com -Status: Open +Status: Feedback Bug Type: Reproducible crash Operating System: Redhat Linux 7.2 PHP Version: 4.2.1 New Comment: Firs try this snapshot: http://snaps.php.net/php4-latest.tar.gz And if it does not work, give a short, complete and standalone script which can easily be used to reproduce this. As it seems the crash happens in split(), come up with such script that does NOT include anything but it and the data that crashes it. Previous Comments: ------------------------------------------------------------------------ [2002-07-18 17:06:15] acs@hourglassone.com Looks like you're correct.. I added a trim() around the second paramater of split() and it seems to take care of it. It would seem that there's no checking done on the size parameter in php_split before calling add_next_index_stringl for the last value. line number is ext/standard/reg.c:574 in php4.2.2dev Snippet of code (offending line marked by >>>> <<<<), $sHeader is returned by curl_exec): class HeaderObj { function HeaderObj($sHeader) { $this->header = $sHeader; $aHeaders = Array(); >>>> $aLines = split("\n",$sHeader); <<<< foreach($aLines as $sLine) { $temp = split(":",trim($sLine)); $aHeaders[$temp[0]] = (isset($temp[1])) ? trim($temp[1]) : ""; if ($temp[0] == "Content-Type") { if (!isset($temp[1])) { $aHeaders[$temp[0]] = trim("text/html"); } } } if (!isset($aHeaders['Content-Type'])) { $aHeaders['Content-Type'] = "text/html"; } $this->headers = $aHeaders; $this->headers['string'] = $sHeader; reset($this->headers); } } --- If I put it in a trim(), with --enable-debug, I get this warning: <b>Warning</b>: String is not zero-terminated (HTTP/1.1 200 OK Date: Thu, 18 Jul 2002 20:58:13 GMT Server: Apache/1.3.23 (Unix) Last-Modified: Fri, 28 Jun 2002 23:00:30 GMT ETag: "736-3d1cea8e" Accept-Ranges: bytes Content-Length: 1846 Content-Type: application/x-javascript Toolbar=search; siteinfopopup=siteinfo; relatedlinkspopup=relatedlinks; twym=webyoumade; searchMethod=Yahoo; twym_disabled=false; ALXSID=ccd89a2e038361a7cb25c7f27130ed86; twym65=D4ABCAC7DEF19AA7979F60CED1A3%2521D7AED1C9EBED9CA59DA7A6DE9099A2E7%2521DB6C8FD3EBE1%2521C5ACD5C5E5DBAF9CA7AB9399C4A5ABA8A89D%2521D1B2D4D5E5A89CA2A1; aid=iKy4Z0eeh000NE Host: client.alexa.com:2222 Pragma: no-cache Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, */* Referer: http://client.alexa.com/speed_test/index.html Accept-Language: en-us @) (source: zend_execute_API.c:274) in <b>Unknown</b> on line <b>0</b><br /> ------------------------------------------------------------------------ [2002-07-18 16:31:05] derick@php.net It crashes on a split function, can you try to shorten your script to narrow the search for us? Derick ------------------------------------------------------------------------ [2002-07-18 16:24:04] acs@hourglassone.com I have a script that proxies a request through Curl to an instance of apache running on the same machine with a different port number. This script worked great until I installed 4.2.1. Error logs show: FATAL: emalloc(): Unable to allocate -491 bytes I'm not entirely sure where the error is being caused. The script in question is using curl, xpath, and mysql. Running HTTPD with -X under gdb yields this backtrace: #0 0x4010da01 in __kill () from /lib/i686/libc.so.6 #1 0x404a9a51 in _emalloc (size=4294966827, __zend_filename=0x405aaa60 "zend_API.c", __zend_lineno=845, __zend_orig_filename=0x0, __zend_orig_lineno=0) at zend_alloc.c:173 #2 0x404aa17d in _estrndup (s=0x814a3a3 "", length=4294966826, __zend_filename=0x405aaa60 "zend_API.c", __zend_lineno=845, __zend_orig_filename=0x0, __zend_orig_lineno=0) at zend_alloc.c:340 #3 0x404c949a in add_next_index_stringl (arg=0x814bde4, str=0x814a3a3 "", length=4294966826, duplicate=1) at zend_API.c:845 #4 0x40555489 in php_split (ht=2, return_value=0x814bde4, this_ptr=0x0, return_value_used=1, icase=0) at reg.c:594 #5 0x405554b0 in zif_split (ht=2, return_value=0x814bde4, this_ptr=0x0, return_value_used=1) at reg.c:604 #6 0x404b6455 in execute (op_array=0x812ac8c) at ./zend_execute.c:1598 #7 0x404b6667 in execute (op_array=0x8134b94) at ./zend_execute.c:1638 #8 0x404b6667 in execute (op_array=0x8138674) at ./zend_execute.c:1638 #9 0x404b6667 in execute (op_array=0x8121de4) at ./zend_execute.c:1638 #10 0x404c70a8 in zend_execute_scripts (type=8, retval=0x0, file_count=3) at zend.c:810 #11 0x404d98ca in php_execute_script (primary_file=0xbffff5b0) at main.c:1381 #12 0x404d4316 in apache_php_module_main (r=0x8115cec, display_source_mode=0) at sapi_apache.c:90 #13 0x404d5184 in send_php (r=0x8115cec, display_source_mode=0, filename=0x81179e4 "/www/redir.php") at mod_php4.c:575 #14 0x404d51f1 in send_parsed_php (r=0x8115cec) at mod_php4.c:590 #15 0x08054757 in ap_invoke_handler () #16 0x080695af in process_request_internal () #17 0x08069610 in ap_process_request () #18 0x08060799 in child_main () #19 0x08060968 in make_child () #20 0x08060adc in startup_children () #21 0x08061154 in standalone_main () #22 0x080619c3 in main () #23 0x400fb507 in __libc_start_main (main=0x8061610 <main>, argc=3, ubp_av=0xbffff9e4, init=0x804ebd4 <_init>, fini=0x8080c40 <_fini>, rtld_fini=0x4000dc14 <_dl_fini>, stack_end=0xbffff9dc) at ../sysdeps/generic/libc-start.c:129 ------------------------------------------------------------------------ -- Edit this bug report at http://bugs.php.net/?id=18422&edit=1

« previous php.bugs (#14568) next »