Bug #67151 [NEW]: strtr with empty array crashes
| From: | nikic@php.net | Date: | Tue, 29 Apr 2014 16:34:09 +0000 |
| Subject: | Bug #67151 [NEW]: strtr with empty array crashes | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-185506@lists.php.net to get a copy of this message | ||
From: nikic
Operating system:
PHP version: 5.6.0beta1
Package: Reproducible crash
Bug Type: Bug
Bug description:strtr with empty array crashes
Description:
------------
<?php
var_dump(strtr("foo", []));
Valgrind:
==24828== Invalid read of size 1
==24828== at 0x817D0EA: php_strtr_hash (string.c:2836)
==24828== by 0x817DC37: php_strtr_array_do_repl (string.c:3049)
==24828== by 0x817E255: php_strtr_array (string.c:3113)
==24828== by 0x817E412: zif_strtr (string.c:3144)
==24828== by 0x82A7E96: zend_do_fcall_common_helper_SPEC
(zend_vm_execute.h:558)
==24828== by 0x82AD85B: ZEND_DO_FCALL_SPEC_CONST_HANDLER
(zend_vm_execute.h:2585)
==24828== by 0x82A7392: execute_ex (zend_vm_execute.h:363)
==24828== by 0x82A7447: zend_execute (zend_vm_execute.h:388)
==24828== by 0x8266A15: zend_execute_scripts (zend.c:1330)
==24828== by 0x81C77A3: php_execute_script (main.c:2549)
==24828== by 0x831669C: do_cli (php_cli.c:994)
==24828== by 0x8317BF6: main (php_cli.c:1378)
==24828== Address 0x43fb16d is 3 bytes before a block of size 4
alloc'd
==24828== at 0x402BE68: malloc (in
/usr/lib/valgrind/vgpreload_memcheck-x86-linux.so)
==24828== by 0x822C278: _emalloc (zend_alloc.c:2427)
==24828== by 0x822C795: _estrndup (zend_alloc.c:2650)
==24828== by 0x82624DD: _zval_copy_ctor_func (zend_variables.c:126)
==24828== by 0x82A1BF1: _zval_copy_ctor (zend_variables.h:45)
==24828== by 0x82ADC3E: ZEND_SEND_VAL_SPEC_CONST_HANDLER
(zend_vm_execute.h:2754)
==24828== by 0x82A7392: execute_ex (zend_vm_execute.h:363)
==24828== by 0x82A7447: zend_execute (zend_vm_execute.h:388)
==24828== by 0x8266A15: zend_execute_scripts (zend.c:1330)
==24828== by 0x81C77A3: php_execute_script (main.c:2549)
==24828== by 0x831669C: do_cli (php_cli.c:994)
==24828== by 0x8317BF6: main (php_cli.c:1378)
==24828==
string(3) "foo"
==24828==
==24828== HEAP SUMMARY:
==24828== in use at exit: 0 bytes in 0 blocks
==24828== total heap usage: 12,026 allocs, 12,026 frees, 1,114,247
bytes allocated
==24828==
==24828== All heap blocks were freed -- no leaks are possible
==24828==
==24828== For counts of detected and suppressed errors, rerun with: -v
==24828== ERROR SUMMARY: 2 errors from 1 contexts (suppressed: 0 from 0)
--
Edit bug report at https://bugs.php.net/bug.php?id=67151&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=67151&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=67151&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=67151&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=67151&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=67151&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=67151&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=67151&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=67151&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=67151&r=support
Expected behavior: https://bugs.php.net/fix.php?id=67151&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=67151&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=67151&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=67151&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=67151&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=67151&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=67151&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=67151&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=67151&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=67151&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=67151&r=mysqlcfg