Bug #65901 [NEW]: ArrayObject causes symbolic table corruption
| From: | vgabor at vgabor dot com | Date: | Tue, 15 Oct 2013 17:00:19 +0000 |
| Subject: | Bug #65901 [NEW]: ArrayObject causes symbolic table corruption | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-182288@lists.php.net to get a copy of this message | ||
From: vgabor at vgabor dot com
Operating system: Linux/Debian
PHP version: Irrelevant
Package: SPL related
Bug Type: Bug
Bug description:ArrayObject causes symbolic table corruption
Description:
------------
In specific circumstances ArrayObject causes symbolic table corruption
(current scope and independent function scope as well)
The main cause: if you set an array element on ArrayObject with null key
(see test script)
$x = new ArrayObject;
...
$x[null]['bar'] = 'foo';
From now on all array access to non existing keys are corrupted.
$a = array('a' => 'aa');
$a['b'] will return the $a itself.
tested version: 5.4.4-14+deb7u4
Test script:
---------------
##########################################
$a = array('a' => 'aa');
$x = new ArrayObject;
$x[null] = array();
$x[null]['bar'] = 'foo'; ### this causes it
# ----------------------------------------
function f($k) {
$f = array('f' => 'ff');
return $f[$k];
}
echo "ArrayObject dump:\n";
var_dump($x);
echo "Non-existing array elements (current scope, function scope)\n";
var_dump($a['b'], f('b'));
echo "Define a new variable: \$s='hohohoooo'\n";
$s = 'hohohoooo';
var_dump($a['b'], f('b'));
echo "Define a new variable: \$n=1\n";
$n = 1;
var_dump($a['b'], f('b'));
##########################################
Expected result:
----------------
ArrayObject dump:
object(ArrayObject)[8]
public '' =>
array (size=1)
'bar' => string 'foo' (length=3)
Non-existing array elements (current scope, function scope)
null
null
Define a new variable: $s='hohohoooo'
null
null
Define a new variable: $n=1
null
null
Actual result:
--------------
ArrayObject dump:
object(ArrayObject)[8]
array (size=0)
empty
Non-existing array elements (current scope, function scope)
array (size=1)
'bar' => string 'foo' (length=3)
array (size=1)
'bar' => string 'foo' (length=3)
Define a new variable: $s='hohohoooo'
string 'hohohoooo' (length=9)
string 'hohohoooo' (length=9)
Define a new variable: $n=1
int 1
int 1
--
Edit bug report at https://bugs.php.net/bug.php?id=65901&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=65901&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=65901&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=65901&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=65901&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=65901&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=65901&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=65901&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=65901&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=65901&r=support
Expected behavior: https://bugs.php.net/fix.php?id=65901&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=65901&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=65901&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=65901&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=65901&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=65901&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=65901&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=65901&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=65901&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=65901&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=65901&r=mysqlcfg