Bug #66751 [Com]: php_strip_whitespace causes segmentation fault

From: Date: Mon, 24 Mar 2014 13:27:47 +0000
Subject: Bug #66751 [Com]: php_strip_whitespace causes segmentation fault
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-184865@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=66751&edit=1

 ID:                 66751
 Comment by:         ivan dot enderlin at hoa-project dot net
 Reported by:        yu at hoaxster dot net
 Summary:            php_strip_whitespace causes segmentation fault
 Status:             Open
 Type:               Bug
 Package:            *General Issues
 Operating System:   OS X Mavericks
 PHP Version:        5.6.0alpha2
 Block user comment: N
 Private report:     N

 New Comment:

Any news from this bug?


Previous Comments:
------------------------------------------------------------------------
[2014-03-05 01:07:10] cidsphere at gmail dot com

I can reproduce this bug in php-5.6.0alpha3 on Ubuntu 13.10 with PHP compiled from source.

The function php_strip_whitespace is used in Composer to generate autoload file. I find it
impossible to use Composer because of this bug.

------------------------------------------------------------------------
[2014-02-24 19:54:36] krakjoe@php.net

This is a bit strange ...

diff --git a/Zend/zend_highlight.c b/Zend/zend_highlight.c
index e4f8d02..b961104 100644
--- a/Zend/zend_highlight.c
+++ b/Zend/zend_highlight.c
@@ -211,7 +211,8 @@ ZEND_API void zend_strip(TSRMLS_D)
                                        break;
 
                                default:
-                                       efree(token.value.str.val);
+                                       if (token.value.str.len)
+                                               efree(token.value.str.val);
                                        break;
                        }
                }

You wouldn't think this is necessary, so I won't submit this as a patch ...

Just a note really, I couldn't make this segfault but there is a call to efree an invalid
pointer.

/me leaves this for someone else who has more of a clue ...

------------------------------------------------------------------------
[2014-02-21 12:01:16] yu at hoaxster dot net

Description:
------------
php_strip_whitespace causes segmentation fault while parsing __CLASS__.

Test script:
---------------
# cat test.php
<?php __CLASS__ ?>

# php -r 'php_strip_whitespace(getcwd()."/test.php");'

Actual result:
--------------
[Fri Feb 21 20:57:50 2014]  Script:  '-'
---------------------------------------
/var/tmp/php-build/source/5.6.0alpha2/Zend/zend_highlight.c(214) : Block 0x10781c048 status:
Invalid pointer: ((size=0x0002b5a5) != (next.prev=0x444d4f4400000001))
Invalid pointer: ((prev=0x00000001) != (prev.size=0x0002b5a5))


------------------------------------------------------------------------



-- 
Edit this bug report at https://bugs.php.net/bug.php?id=66751&edit=1


Thread (5 messages)

« previous php.bugs (#184865) next »