Bug #67297 [NEW]: Pdo-MySql Insert (escaping) bug

From: Date: Sat, 17 May 2014 11:41:10 +0000
Subject: Bug #67297 [NEW]: Pdo-MySql Insert (escaping) bug
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-185845@lists.php.net to get a copy of this message
From: genuser at gmx dot net Operating system: Debian GNU/Linux 7.5 (wheezy) PHP version: 5.5.12 Package: PCRE related Bug Type: Bug Bug description:Pdo-MySql Insert (escaping) bug Description: ------------ Hey there, php running into an segmentation fault. I try to insert a json record into my database and mybe pcre become a problem by escaping? Test script: --------------- I'm try to import this by Mysql Pdo. Example-Part of sql insert: '{\"WahlartenLang\":\"\",\"WahlartenKurz\":\"RG,KT,GR,GR+\",\"PostfreimachungVersandta\":\"0\",\"Wahlkreisnummer\":\"09\",\"Wahlbezirksnummer\":\"05041\",\"Waehlernummer\":\"110\",\"Familienname\":\"Schm\\u00f6lling\",\"Vorname\":\"Patrick\",\"Strassenschluessel\":\"76018\", ............ Expected result: ---------------- Successful database insert and no segmentation fault. Actual result: -------------- ============================= Program received signal SIGSEGV, Segmentation fault. ============================= 0x000000000048343b in match (eptr=0x18257d2 "785);\n;", ecode=0x122b797 "\035\"x", mstart=0x1822719 "\"WahlartenLang\\\":\\\"\\\",\\\"WahlartenKurz\\\":\\\"RG,KT,GR,GR+\\\",\\\"PostfreimachungVersandta\\\":\\\"0\\\",\\\"Wahlkreisnummer\\\":\\\"09\\\",\\\"Wahlbezirksnummer\\\":\\\"05041\\\",\\\"Waehlernummer\\\":\\\"110\\\",\\\"Familienname\\\":\\\"Schm"..., offset_top=4, md=0x7fffffff90a0, eptrb=0x0, rdepth=10890) at /usr/src/php5.5/source/php5-5.5.12/ext/pcre/pcrelib/pcre_exec.c:1802 1802 /usr/src/php5.5/source/php5-5.5.12/ext/pcre/pcrelib/pcre_exec.c: Datei oder Verzeichnis nicht gefunden. ============================= Part of Backtrace ============================= #0 0x000000000048343b in match (eptr=0x18257d2 "785);\n;", ecode=0x122b797 "\035\"x", mstart=0x1822719 "\"WahlartenLang\\\":\\\"\\\",\\\"WahlartenKurz\\\":\\\"RG,KT,GR,GR+\\\",\\\"PostfreimachungVersandta\\\":\\\"0\\\",\\\"Wahlkreisnummer\\\":\\\"09\\\",\\\"Wahlbezirksnummer\\\":\\\"05041\\\",\\\"Waehlernummer\\\":\\\"110\\\",\\\"Familienname\\\":\\\"Schm"..., offset_top=4, md=0x7fffffff90a0, eptrb=0x0, rdepth=10890) at /usr/src/php5.5/source/php5-5.5.12/ext/pcre/pcrelib/pcre_exec.c:1802 #1 0x0000000000493f0e in match (eptr=0x18257d2 "785);\n;", ecode=0x122b794 "z", mstart=0x1822719 "\"WahlartenLang\\\":\\\"\\\",\\\"WahlartenKurz\\\":\\\"RG,KT,GR,GR+\\\",\\\"PostfreimachungVersandta\\\":\\\"0\\\",\\\"Wahlkreisnummer\\\":\\\"09\\\",\\\"Wahlbezirksnummer\\\":\\\"05041\\\",\\\"Waehlernummer\\\":\\\"110\\\",\\\"Familienname\\\":\\\"Schm"..., offset_top=4, md=<optimized out>, eptrb=0x0, rdepth=10889) at /usr/src/php5.5/source/php5-5.5.12/ext/pcre/pcrelib/pcre_exec.c:2024 . . . . . #10891 0x000000000049524f in php_pcre_exec (argument_re=0x122b740, extra_data=extra_data@entry=0x7fffffff9310, subject=subject@entry=0x18226c0 "INSERT INTO job_detail \n(job_id, print_id, state_date, record, state_id) \nVALUES \n(,,,'{\\\"WahlartenLang\\\":\\\"\\\",\\\"WahlartenKurz\\\":\\\"RG,KT,GR,GR+\\\",\\\"PostfreimachungVersandta\\\":\\\"0\\\",\\\"Wahlkreisnummer\\\""..., length=length@entry=12569, start_offset=start_offset@entry=0, options=0, offsets=offsets@entry=0x142ba28, offsetcount=offsetcount@entry=6) at /usr/src/php5.5/source/php5-5.5.12/ext/pcre/pcrelib/pcre_exec.c:6945 #10892 0x000000000049aed3 in php_pcre_replace_impl (pce=0x122b820, subject=0x18226c0 "INSERT INTO job_detail \n(job_id, print_id, state_date, record, state_id) \nVALUES \n(,,,'{\\\"WahlartenLang\\\":\\\"\\\",\\\"WahlartenKurz\\\":\\\"RG,KT,GR,GR+\\\",\\\"PostfreimachungVersandta\\\":\\\"0\\\",\\\"Wahlkreisnummer\\\""..., subject_len=12569, replace_val=replace_val@entry=0x17d1a20, is_callable_replace=is_callable_replace@entry=0, result_len=0x7fffffff9450, limit=-1, replace_count=0x7fffffff9454) at /usr/src/php5.5/source/php5-5.5.12/ext/pcre/php_pcre.c:1091 #10893 0x000000000049bc5f in php_pcre_replace (regex=<optimized out>, regex_len=<optimized out>, subject=<optimized out>, subject_len=<optimized out>, replace_val=replace_val@entry=0x17d1a20, is_callable_replace=is_callable_replace@entry=0, result_len=0x7fffffffffff, result_len@entry=0x7fffffff9450, limit=-27564, limit@entry=-1, replace_count=replace_count@entry=0x7fffffff9454) at /usr/src/php5.5/source/php5-5.5.12/ext/pcre/php_pcre.c:997 -- Edit bug report at https://bugs.php.net/bug.php?id=67297&edit=1 -- Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=67297&r=trysnapshot54 Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=67297&r=trysnapshot55 Try a snapshot (trunk): https://bugs.php.net/fix.php?id=67297&r=trysnapshottrunk Fixed in SVN: https://bugs.php.net/fix.php?id=67297&r=fixed Fixed in release: https://bugs.php.net/fix.php?id=67297&r=alreadyfixed Need backtrace: https://bugs.php.net/fix.php?id=67297&r=needtrace Need Reproduce Script: https://bugs.php.net/fix.php?id=67297&r=needscript Try newer version: https://bugs.php.net/fix.php?id=67297&r=oldversion Not developer issue: https://bugs.php.net/fix.php?id=67297&r=support Expected behavior: https://bugs.php.net/fix.php?id=67297&r=notwrong Not enough info: https://bugs.php.net/fix.php?id=67297&r=notenoughinfo Submitted twice: https://bugs.php.net/fix.php?id=67297&r=submittedtwice register_globals: https://bugs.php.net/fix.php?id=67297&r=globals PHP 4 support discontinued: https://bugs.php.net/fix.php?id=67297&r=php4 Daylight Savings: https://bugs.php.net/fix.php?id=67297&r=dst IIS Stability: https://bugs.php.net/fix.php?id=67297&r=isapi Install GNU Sed: https://bugs.php.net/fix.php?id=67297&r=gnused Floating point limitations: https://bugs.php.net/fix.php?id=67297&r=float No Zend Extensions: https://bugs.php.net/fix.php?id=67297&r=nozend MySQL Configuration Error: https://bugs.php.net/fix.php?id=67297&r=mysqlcfg

« previous php.bugs (#185845) next »