Bug #66751 [Opn]: php_strip_whitespace causes segmentation fault
| From: | krakjoe@php.net | Date: | Mon, 24 Feb 2014 19:54:37 +0000 |
| Subject: | Bug #66751 [Opn]: php_strip_whitespace causes segmentation fault | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-184397@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=66751&edit=1
ID: 66751
Updated by: krakjoe@php.net
Reported by: yu at hoaxster dot net
Summary: php_strip_whitespace causes segmentation fault
Status: Open
Type: Bug
Package: *General Issues
Operating System: OS X Mavericks
PHP Version: 5.6.0alpha2
Block user comment: N
Private report: N
New Comment:
This is a bit strange ...
diff --git a/Zend/zend_highlight.c b/Zend/zend_highlight.c
index e4f8d02..b961104 100644
--- a/Zend/zend_highlight.c
+++ b/Zend/zend_highlight.c
@@ -211,7 +211,8 @@ ZEND_API void zend_strip(TSRMLS_D)
break;
default:
- efree(token.value.str.val);
+ if (token.value.str.len)
+ efree(token.value.str.val);
break;
}
}
You wouldn't think this is necessary, so I won't submit this as a patch ...
Just a note really, I couldn't make this segfault but there is a call to efree an invalid
pointer.
/me leaves this for someone else who has more of a clue ...
Previous Comments:
------------------------------------------------------------------------
[2014-02-21 12:01:16] yu at hoaxster dot net
Description:
------------
php_strip_whitespace causes segmentation fault while parsing __CLASS__.
Test script:
---------------
# cat test.php
<?php __CLASS__ ?>
# php -r 'php_strip_whitespace(getcwd()."/test.php");'
Actual result:
--------------
[Fri Feb 21 20:57:50 2014] Script: '-'
---------------------------------------
/var/tmp/php-build/source/5.6.0alpha2/Zend/zend_highlight.c(214) : Block 0x10781c048 status:
Invalid pointer: ((size=0x0002b5a5) != (next.prev=0x444d4f4400000001))
Invalid pointer: ((prev=0x00000001) != (prev.size=0x0002b5a5))
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=66751&edit=1