Bug #65901 [Opn->Csd]: ArrayObject causes symbolic table corruption
| From: | nikic@php.net | Date: | Tue, 15 Oct 2013 17:25:38 +0000 |
| Subject: | Bug #65901 [Opn->Csd]: ArrayObject causes symbolic table corruption | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-182293@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=65901&edit=1
ID: 65901
Updated by: nikic@php.net
Reported by: vgabor at vgabor dot com
Summary: ArrayObject causes symbolic table corruption
-Status: Open
+Status: Closed
Type: Bug
Package: SPL related
Operating System: Linux/Debian
PHP Version: Irrelevant
-Assigned To:
+Assigned To: nikic
Block user comment: N
Private report: N
New Comment:
This was fixed in PHP 5.4.8, see http://3v4l.org/p0fnK.
Previous Comments:
------------------------------------------------------------------------
[2013-10-15 17:00:19] vgabor at vgabor dot com
Description:
------------
In specific circumstances ArrayObject causes symbolic table corruption (current scope and
independent function scope as well)
The main cause: if you set an array element on ArrayObject with null key (see test script)
$x = new ArrayObject;
...
$x[null]['bar'] = 'foo';
From now on all array access to non existing keys are corrupted.
$a = array('a' => 'aa');
$a['b'] will return the $a itself.
tested version: 5.4.4-14+deb7u4
Test script:
---------------
##########################################
$a = array('a' => 'aa');
$x = new ArrayObject;
$x[null] = array();
$x[null]['bar'] = 'foo'; ### this causes it
# ----------------------------------------
function f($k) {
$f = array('f' => 'ff');
return $f[$k];
}
echo "ArrayObject dump:\n";
var_dump($x);
echo "Non-existing array elements (current scope, function scope)\n";
var_dump($a['b'], f('b'));
echo "Define a new variable: \$s='hohohoooo'\n";
$s = 'hohohoooo';
var_dump($a['b'], f('b'));
echo "Define a new variable: \$n=1\n";
$n = 1;
var_dump($a['b'], f('b'));
##########################################
Expected result:
----------------
ArrayObject dump:
object(ArrayObject)[8]
public '' =>
array (size=1)
'bar' => string 'foo' (length=3)
Non-existing array elements (current scope, function scope)
null
null
Define a new variable: $s='hohohoooo'
null
null
Define a new variable: $n=1
null
null
Actual result:
--------------
ArrayObject dump:
object(ArrayObject)[8]
array (size=0)
empty
Non-existing array elements (current scope, function scope)
array (size=1)
'bar' => string 'foo' (length=3)
array (size=1)
'bar' => string 'foo' (length=3)
Define a new variable: $s='hohohoooo'
string 'hohohoooo' (length=9)
string 'hohohoooo' (length=9)
Define a new variable: $n=1
int 1
int 1
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=65901&edit=1