#18814 [NEW]: Segfault variable swap

From: Date: Thu, 08 Aug 2002 19:35:49 +0000
Subject: #18814 [NEW]: Segfault variable swap
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-16316@lists.php.net to get a copy of this message
From: andersena@netscape.net Operating system: Linux 2.4.18 (Mandrake 8.1) PHP version: 4.2.2 PHP Bug Type: Scripting Engine problem Bug description: Segfault variable swap <?php $data = array ("Line 1", "Line 10"); foreach ($data as $subject) { $temp = ""; $temp = stripslashes ($subject); $line = "$temp"; } ?> The following script causes a seg fault on the second loop iteration. <?php $data = array ("Line 1", "Line 10"); foreach ($data as $subject) { $temp = ""; $temp = stripslashes ($subject); $line = "$temp"; } ?> Changing any element of the script will make it work properly. I'm running Mandrake 8.1 on a Gateway E3400, Gateway E-3100, and Dell 2400. This script segfaults on all of them when using PHP 4.2.2. If I use PHP 4.2.1, everything is fine. It makes no difference whether I'm running a standalone PHP or using Apache 1.3.26. The results are the same. I use the same PHP.INI file for both versions (I don't replace/change it). Module information is as follows: # # Run 1st time to create apache dynamic module. # Remove the following if you don't use SSL: # CPPFLAGS= # #cd $HOMEDIR #tar -xvzf $PHP.tar.gz #rm -rf $SRC_DIR/$PHP #mv $PHP $SRC_DIR #cd $SRC_DIR/$PHP #CPPFLAGS=-DEAPI \ #./configure --enable-shared \ # --enable-track-vars \ # --enable-versioning \ # --with-apxs=$APACHEDIR/bin/apxs \ # --with-config-file-path=/usr/local/lib \ # --with-mysql \ # --with-pgsql \ # --with-sybase=/usr/local/$FREETDS \ # --with-pdflib=/usr/local \ # --with-zlib-dir=/usr #make #$APACHEDIR/bin/apachectl stop #make install #$APACHEDIR/bin/apachectl start # # Run 2nd time to create standalone executable. # The difference between this and the 1st time # is the CPPFLAGS and --with-apxs, and graphics # modules to play with. # #cd $HOMEDIR #tar -xvzf $PHP.tar.gz #rm -rf $SRC_DIR/$PHP #mv $PHP $SRC_DIR #cd $SRC_DIR/$PHP #./configure --enable-calendar \ # --enable-dbase \ # --enable-force-cgi-redirect \ # --enable-ftp \ # --with-gd \ # --with-jpeg-dir=/usr/lib \ # --enable-shared \ # --enable-track-vars \ # --enable-versioning \ # --with-config-file-path=/usr/local/lib \ # --with-mysql \ # --with-pgsql \ # --with-png-dir=/usr/lib \ # --with-sybase=/usr/local/$FREETDS \ # --with-zlib-dir=/usr/lib #make #make install The core dump gives me the following information: (gdb) bt #0 0x401dc1da in free () from /lib/libc.so.6 #1 0x401dbf44 in free () from /lib/libc.so.6 #2 0x080f5c43 in shutdown_memory_manager (silent=0, clean_cache=0) at zend_alloc.c:468 #3 0x08066a3a in php_request_shutdown (dummy=0x0) at main.c:794 #4 0x080657cf in main (argc=2, argv=0xbffff7c4) at cgi_main.c:827 #5 0x401775b0 in __libc_start_main () from /lib/libc.so.6 (gdb) Re-Compiling with --enable-debug results in no core file, and this message: [Thu Aug 8 12:03:33 2002] Script: 'test.php' --------------------------------------- ./zend_execute.c(445) : Block 0x082061A8 status: zend_variables.c(44) : Actual location (location was relayed) Beginning: OK (allocated on string.c:2262, 7 bytes) End: Overflown (magic=0x2A8FCC00 instead of 0x2A8FCC84) 1 byte(s) overflown --------------------------------------- Content-type: text/html [Thu Aug 8 12:03:33 2002] Script: 'test.php' --------------------------------------- zend_execute_API.c(274) : Block 0x08206708 status: zend_variables.c(44) : Actual location (location was relayed) Beginning: OK (allocated on string.c:2262, 8 bytes) End: Overflown (magic=0x2A8FCC00 instead of 0x2A8FCC84) 1 byte(s) overflown --------------------------------------- string.c(2262) : Freeing 0x0820672C (8 bytes), script=test.php Last leak repeated 1 time [EOM] -- Edit bug report at http://bugs.php.net/?id=18814&edit=1 -- Fixed in CVS: http://bugs.php.net/fix.php?id=18814&r=fixedcvs Fixed in release: http://bugs.php.net/fix.php?id=18814&r=alreadyfixed Need backtrace: http://bugs.php.net/fix.php?id=18814&r=needtrace Try newer version: http://bugs.php.net/fix.php?id=18814&r=oldversion Not developer issue: http://bugs.php.net/fix.php?id=18814&r=support Expected behavior: http://bugs.php.net/fix.php?id=18814&r=notwrong Not enough info: http://bugs.php.net/fix.php?id=18814&r=notenoughinfo Submitted twice: http://bugs.php.net/fix.php?id=18814&r=submittedtwice register_globals: http://bugs.php.net/fix.php?id=18814&r=globals

« previous php.bugs (#16316) next »