Bug #67919 [NEW]: zend_mm_heap corrupted when a bound out parameter preset to a constant
| From: | pm at datasphere dot ch | Date: | Wed, 27 Aug 2014 18:15:11 +0000 |
| Subject: | Bug #67919 [NEW]: zend_mm_heap corrupted when a bound out parameter preset to a constant | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-187302@lists.php.net to get a copy of this message | ||
From: pm at datasphere dot ch
Operating system: Linux
PHP version: 5.5.16
Package: PDO ODBC
Bug Type: Bug
Bug description:zend_mm_heap corrupted when a bound out parameter preset to a constant
Description:
------------
When a out/inout bound parameter is set to a string constant before
executing a prepared executed statement, a call to erealloc() on it
fails.
Test script:
---------------
<?php
try {
$conn = new PDO("odbc:<yourdatabaseDSN>");
}
catch (PDOException $e) {
print "Error!: " . $e->getMessage() . "\n";
die();
}
/* Adjust the SQL statement below to your test environment. */
$stmt = $conn->prepare("CALL LIBRARY.GETDB(? , ?)");
$intvalue = 10;
$strvalue = "abc";
$stmt->bindParam(1, $intvalue, PDO::PARAM_INT|PDO::PARAM_INPUT_OUTPUT,
4);
$stmt->bindParam(2, $strvalue, PDO::PARAM_STR|PDO::PARAM_INPUT_OUTPUT,
100);
print "before execute\n";
$res = $stmt->execute();
print "after execute\n";
var_dump($intvalue);
var_dump($strvalue);
?>
Expected result:
----------------
Proper execution and normal program exit
Actual result:
--------------
zend_mm_heap corrupted
--
Edit bug report at https://bugs.php.net/bug.php?id=67919&edit=1
--