Bug #52797 [Opn->Fbk]: crash because of double free

From: Date: Sat, 29 Jan 2011 10:31:48 +0000
Subject: Bug #52797 [Opn->Fbk]: crash because of double free
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-158308@lists.php.net to get a copy of this message
Edit report at http://bugs.php.net/bug.php?id=52797&edit=1

 ID:                 52797
 Updated by:         felipe@php.net
 Reported by:        hossy421 at yahoo dot co dot jp
 Summary:            crash because of double free
-Status:             Open
+Status:             Feedback
 Type:               Bug
 Package:            Reproducible crash
 Operating System:   FreeBSD 7.3-RELEASE-p2
 PHP Version:        5.3.3
 Block user comment: N
 Private report:     N

 New Comment:

Please try using this snapshot:

  http://snaps.php.net/php5.3-latest.tar.gz
 
For Windows:

  http://windows.php.net/snapshots/




Previous Comments:
------------------------------------------------------------------------
[2010-09-08 15:18:45] hossy421 at yahoo dot co dot jp

Description:
------------
httpd ( Apache 2.2 ) crashes below messages.

> pid XXXXX(httpd), uid 80: exited on signal 11

XXXXX is process id of a httpd child process.


Test script:
---------------
independent of script.
httpd is crashed by any script.
for example PukiWiki.

Expected result:
----------------
all script will run without any error.

Actual result:
--------------
I've compiled PHP with --enable-debug option.
PHP crash with below message.

> ---------------------------------------
> Zend/zend_language_scanner.l(704) : Block 0x28f9871c status:
> Beginning:      Freed
>     Start:      OK
>       End:      Overflown (magic=0x0000003C instead of 0xC5F842B3)
>                 At least 4 bytes overflown
> ---------------------------------------

Zend/zend_language_scanner.l(704) is below code.
> efree(SCNG(script_org));

SCNG(script_org)' is saved by zend_save_lexical_state()' function,
and restored by `zend_restore_lexical_state()' function.

SCNG(script_org)' is unsigned char*',
but only the pointers are stored and saved, not the string pointed to.



------------------------------------------------------------------------



-- 
Edit this bug report at http://bugs.php.net/bug.php?id=52797&edit=1


Thread (6 messages)

« previous php.bugs (#158308) next »