#18813 [NEW]: Segfault variable swap
| From: | andersena at netscape dot net | Date: | Thu, 08 Aug 2002 19:32:44 +0000 |
| Subject: | #18813 [NEW]: Segfault variable swap | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-16314@lists.php.net to get a copy of this message | ||
From: andersena@netscape.net
Operating system: Linux 2.4.18 (Mandrake 8.1)
PHP version: 4.2.2
PHP Bug Type: Scripting Engine problem
Bug description: Segfault variable swap
The following script causes a seg fault on the second loop iteration.
<?php
$data = array ("Line 1",
"Line 10");
foreach ($data as $subject)
{
$temp = "";
$temp = stripslashes ($subject);
$line = "$temp";
}
?>
Changing any element of the script will make it work properly. In my
production script, removing stripslashes made everything work OK. However,
I need stripslashes (am using DB query instead of an array).
I'm running Mandrake 8.1 on a Gateway E3400, Gateway E-3100, and Dell
2400.
This script segfaults on all of these machines when using PHP 4.2.2. If I
use PHP 4.2.1, everything is fine. It makes no difference whether I'm
running a standalone PHP or using Apache 1.3.26. The results are the
same.
I use the same PHP.INI file for both versions (I don't replace/change
it).
The core dump gives me the following information:
(gdb) bt
#0 0x401dc1da in free () from /lib/libc.so.6
#1 0x401dbf44 in free () from /lib/libc.so.6
#2 0x080f5c43 in shutdown_memory_manager (silent=0, clean_cache=0) at
zend_alloc.c:468
#3 0x08066a3a in php_request_shutdown (dummy=0x0) at main.c:794
#4 0x080657cf in main (argc=2, argv=0xbffff7c4) at cgi_main.c:827
#5 0x401775b0 in __libc_start_main () from /lib/libc.so.6
(gdb)
Re-Compiling with --enable-debug results in no core file, and this
message:
[Thu Aug 8 12:03:33 2002] Script: 'test.php'
---------------------------------------
./zend_execute.c(445) : Block 0x082061A8 status:
zend_variables.c(44) : Actual location (location was relayed)
Beginning: OK (allocated on string.c:2262, 7 bytes)
End: Overflown (magic=0x2A8FCC00 instead of 0x2A8FCC84)
1 byte(s) overflown
---------------------------------------
Content-type: text/html
[Thu Aug 8 12:03:33 2002] Script: 'test.php'
---------------------------------------
zend_execute_API.c(274) : Block 0x08206708 status:
zend_variables.c(44) : Actual location (location was relayed)
Beginning: OK (allocated on string.c:2262, 8 bytes)
End: Overflown (magic=0x2A8FCC00 instead of 0x2A8FCC84)
1 byte(s) overflown
---------------------------------------
string.c(2262) : Freeing 0x0820672C (8 bytes), script=test.php
Last leak repeated 1 time
[EOM]
--
Edit bug report at http://bugs.php.net/?id=18813&edit=1
--
Fixed in CVS: http://bugs.php.net/fix.php?id=18813&r=fixedcvs
Fixed in release: http://bugs.php.net/fix.php?id=18813&r=alreadyfixed
Need backtrace: http://bugs.php.net/fix.php?id=18813&r=needtrace
Try newer version: http://bugs.php.net/fix.php?id=18813&r=oldversion
Not developer issue: http://bugs.php.net/fix.php?id=18813&r=support
Expected behavior: http://bugs.php.net/fix.php?id=18813&r=notwrong
Not enough info: http://bugs.php.net/fix.php?id=18813&r=notenoughinfo
Submitted twice: http://bugs.php.net/fix.php?id=18813&r=submittedtwice
register_globals: http://bugs.php.net/fix.php?id=18813&r=globals