Bug #18528 Updated: Php crashes upon using eregi_replace
| From: | msopacua at idg dot nl | Date: | Wed, 24 Jul 2002 08:16:48 +0000 |
| Subject: | Bug #18528 Updated: Php crashes upon using eregi_replace | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-15006@lists.php.net to get a copy of this message | ||
ID: 18528
Updated by: msopacua@idg.nl
Reported By: flash@daaw.org
Status: Open
Bug Type: Reproducible crash
Operating System: Redhat linux 7.1 (kernel 2.4.18)
PHP Version: 4.2.2
New Comment:
strike that please - that's the unescaped pipe ('or') I used.
Previous Comments:
------------------------------------------------------------------------
[2002-07-24 04:10:41] msopacua@idg.nl
Derick: I don't think it's an actual crash :-)
He just runs outof memory, not realizing that the meta-character "&" is
'the match' - but the bug is in PHP, as it is resolving the & character
in the result of the operation!
So it seems a recursion eval in ereg functions.
Example:
?php
$text="bla&|&bla2";
$a = eregi_replace("&|&", ":", $text);
$b = str_replace("&|&", ":", $text);
$c = eregi_replace("\\\&|\\\&", ":", $text);
echo "$a\n$b\n$c";
?>
Output:
$ php -f ./tmp.php
bla:|:bla2
bla:bla2
bla&|&bla2
------------------------------------------------------------------------
[2002-07-24 04:03:17] flash@daaw.org
Backtrace (I dont see errors)
[root@lhurgoyf bin]# gdb ./httpd
GNU gdb Red Hat Linux (5.1-0.71)
Copyright 2001 Free Software Foundation, Inc.
GDB is free software, covered by the GNU General Public License, and
you are
welcome to change it and/or distribute copies of it under certain
conditions.
Type "show copying" to see the conditions.
There is absolutely no warranty for GDB. Type "show warranty" for
details.
This GDB was configured as "i386-redhat-linux"...
(gdb) run -X
Starting program: /usr/local/apache/bin/./httpd -X
Program exited with code 01.
(gdb) bt
No stack.
(gdb)
------------------------------------------------------------------------
[2002-07-24 03:50:38] derick@php.net
Please make a backtrace as asked in an earlier reply.
The location with info on how to do this is:
http://bugs.php.net/bugs-generating-backtrace.php
Derick
------------------------------------------------------------------------
[2002-07-24 03:48:51] flash@daaw.org
the apache error log shows:
FATAL: emalloc(): Unable to allocate -133048 bytes
one time each time you refresh the script. so it has something to do
with the crashing.
------------------------------------------------------------------------
[2002-07-24 03:45:25] flash@daaw.org
forgot! im using apache 1.3.26 with php compiled as DSO.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
http://bugs.php.net/18528
--
Edit this bug report at http://bugs.php.net/?id=18528&edit=1