Bug #67245 [ReO->Csd]: usage of memcpy() with overlapping src and dst in zend_exceptions.c

From: Date: Sun, 11 May 2014 13:18:20 +0000
Subject: Bug #67245 [ReO->Csd]: usage of memcpy() with overlapping src and dst in zend_exceptions.c
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-185765@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=67245&edit=1 ID: 67245 Updated by: bwoebi@php.net Reported by: gm dot outside+php at gmail dot com Summary: usage of memcpy() with overlapping src and dst in zend_exceptions.c -Status: Re-Opened +Status: Closed Type: Bug Package: *General Issues Operating System: Linux PHP Version: 5.5.12 Assigned To: bwoebi Block user comment: N Private report: N New Comment: Cherry-picked fix for 5.4 and 5.5. Now everything should be right. Previous Comments: ------------------------------------------------------------------------ [2014-05-11 13:09:10] bwoebi@php.net Oh, wait, I've merged it into the wrong branch, will fix. ------------------------------------------------------------------------ [2014-05-11 12:59:59] bwoebi@php.net That bug had already been fixed in http://git.php.net/?p=php-src.git;a=commitdiff;h=0e273217cfd1e72b5109a880fb4334edd2f61448 … I had noticed it later... ------------------------------------------------------------------------ [2014-05-11 12:27:13] gm dot outside+php at gmail dot com Description: ------------ According to man page for memcpy(3) the function should not be used with overlapping source and destination arguments. A recent update to Zend/zend_exceptions.c (commit: http://git.php.net/?p=php-src.git;a=commitdiff;h=afa03a470ef90a53f2b59a8175f77afdb6b5a651) introduced formatting of trace's arguments where it uses memcpy() with overlapping addresses. This causes issues on at least systems with glibc 2.3.6 and the testsuite on such systems fails. If one replaces memcpy() with memmove() the testsuite will pass again. P.S. I believe that there should be a more efficient way to achieve the string formatting since re-allocating string byte by byte should be very inefficient, but this is unrelated to the bug at hand. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=67245&edit=1

« previous php.bugs (#185765) next »