#18140 [Ver->Csd]: Array key -1 can crash PHP
| From: | stas@php.net | Date: | Thu, 01 Aug 2002 16:07:39 +0000 |
| Subject: | #18140 [Ver->Csd]: Array key -1 can crash PHP | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-15750@lists.php.net to get a copy of this message | ||
ID: 18140
Updated by: stas@php.net
Reported By: carl@thep.lu.se
-Status: Verified
+Status: Closed
Bug Type: Scripting Engine problem
Operating System: Linux
PHP Version: 4.3.0-dev
New Comment:
This bug has been fixed in CVS. You can grab a snapshot of the
CVS version at http://snaps.php.net/. In case this was a
documentation
problem, the fix will show up soon at http://www.php.net/manual/.
In case this was a PHP.net website problem, the change will show
up on the PHP.net site and on the mirror sites.
Thank you for the report, and for helping us make PHP better.
Previous Comments:
------------------------------------------------------------------------
[2002-07-29 09:31:22] nohn@php.net
Verified with 4.3.0-dev on Compaq Tru64/Alpha (CLI) and 4.2.0 on
Solaris 7/Sparc (Apache)
------------------------------------------------------------------------
[2002-07-03 13:21:47] sniper@php.net
Reproduced with latest CVS HEAD on Linux.
------------------------------------------------------------------------
[2002-07-03 13:16:05] jan@php.net
vrified on FreeBSD
#0 zend_fetch_dimension_address (result=0x81e7178, op1=0x81e7188,
op2=0x81e7198, Ts=0xbfbfe6e8, type=1)
at /mnt/data/cvs/php4/Zend/zend_execute_locks.h:8
8 z->refcount++;
(gdb) bt
#0 zend_fetch_dimension_address (result=0x81e7178, op1=0x81e7188,
op2=0x81e7198, Ts=0xbfbfe6e8, type=1)
at /mnt/data/cvs/php4/Zend/zend_execute_locks.h:8
#1 0x8127e0d in execute (op_array=0x81da68c) at
/mnt/data/cvs/php4/Zend/zend_execute.c:1263
#2 0x811c0a0 in zend_execute_scripts (type=8, retval=0x0,
file_count=3) at /mnt/data/cvs/php4/Zend/zend.c:810
#3 0x80fca4a in php_execute_script (primary_file=0xbfbffb1c) at
/mnt/data/cvs/php4/main/main.c:1376
#4 0x81314dd in main (argc=2, argv=0xbfbffb84) at
/mnt/data/cvs/php4/sapi/cli/php_cli.c:674
#5 0x80611c9 in _start ()
------------------------------------------------------------------------
[2002-07-03 12:35:00] sander@php.net
Thank you for this bug report. To properly diagnose the problem, we
need a backtrace to see what is happening behind the scenes. To
find out how to generate a backtrace, please read
http://bugs.php.net/bugs-generating-backtrace.php
Once you have generated a backtrace, please submit it to this bug
report and change the status back to "Open". Thank you for helping
us make PHP better.
Can't reproduce with latest CVS. Can you try the CVS version and
generate a backtrace if possible?
------------------------------------------------------------------------
[2002-07-03 11:50:10] carl@thep.lu.se
If the last key of an array with at least 2 elements is -1,
adding new elements with [] (or array_push) crashes PHP.
Here is the simplest example I could create:
$arr = array(0=>0,-1=>0);
$arr[] = 0;
I haven't tested with the CVS version.
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/?id=18140&edit=1