Bug #54465 [Opn]: PHP crashes when passing large object to string functions
| From: | iliaa@php.net | Date: | Tue, 12 Apr 2011 18:24:31 +0000 |
| Subject: | Bug #54465 [Opn]: PHP crashes when passing large object to string functions | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-160128@lists.php.net to get a copy of this message | ||
Edit report at http://bugs.php.net/bug.php?id=54465&edit=1
ID: 54465
Updated by: iliaa@php.net
Reported by: wwwound at gmail dot com
Summary: PHP crashes when passing large object to string
functions
Status: Open
Type: Bug
Package: Reproducible crash
Operating System: CentOs
PHP Version: 5.3.6
Block user comment: N
Private report: N
New Comment:
The crash is the result of a stack overflow, caused by recursive
function use. The
code will eventually crash even when $foo without strval() is used. It
is just
that with strval() the stack is being more heavily utilized.
Previous Comments:
------------------------------------------------------------------------
[2011-04-05 11:53:33] wwwound at gmail dot com
May be... But if we passing strval($foo) instead of $foo, it works fine
and
recursion doesnt currupt heap or violate memory access
------------------------------------------------------------------------
[2011-04-05 09:21:29] scottmac@php.net
Isn't this just smashing the stack with a recursion 15603 levels deep?
------------------------------------------------------------------------
[2011-04-04 16:04:07] wwwound at gmail dot com
Description:
------------
PHP crashes when passing large object ( with __toString() method ) to
string functions (like substr(), urlencode() etc.)
Test script:
---------------
<?php
class Foo
{
protected $obj;
function rec($i = 0, $obj)
{
$this -> obj = $obj;
// >5603 - segmentation fault or zend_mm_heap corrupted
// With some values can work as expected
if ( $i < 15604) {
$this -> rec(++$i, $this);
}
}
function __toString()
{
$this -> rec(0, $this);
return "Hello, world!";
}
}
$foo = new Foo();
substr($foo, 0, 5);
// This is ok
//echo "\nHello!\n";
// But if we begin using variables "zend_mm_heap corrupted" or
"Segmentation Fault"
$a = "aaaaa\n";
echo $a;
?>
Expected result:
----------------
Expecting correct appication exit
Actual result:
--------------
"Segmentation Fault" or "zend_mm_heap corrupted" errors
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/bug.php?id=54465&edit=1