#18422 [Fbk->Csd]: emalloc() call crashes Apache (backtrace provided)

From: Date: Wed, 11 Sep 2002 16:43:13 +0000
Subject: #18422 [Fbk->Csd]: emalloc() call crashes Apache (backtrace provided)
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-19149@lists.php.net to get a copy of this message
ID: 18422 Updated by: sniper@php.net Reported By: acs@hourglassone.com -Status: Feedback +Status: Closed Bug Type: Reproducible crash Operating System: Redhat Linux 7.2 PHP Version: 4.2.1 New Comment: No feedback..should be fixed in 4.2.3 though. Previous Comments: ------------------------------------------------------------------------ [2002-07-18 19:25:31] sniper@php.net If it's not fixed in the snapshot (might not be) please provide us the patch against it (diff -u) and add it here.. ------------------------------------------------------------------------ [2002-07-18 18:52:23] acs@hourglassone.com More info: I managed to solve the problem by applying the following: 593,595c593,595 < < add_next_index_stringl(return_value, strp, size, 1); < --- > if (size > 0) { > add_next_index_stringl(return_value, strp, size, 1); > } Don't know if this is a good solution or not. I will try the latest snapshot tomorrow and see if the problem is solved. Cheers. ------------------------------------------------------------------------ [2002-07-18 17:52:48] sniper@php.net Firs try this snapshot: http://snaps.php.net/php4-latest.tar.gz And if it does not work, give a short, complete and standalone script which can easily be used to reproduce this. As it seems the crash happens in split(), come up with such script that does NOT include anything but it and the data that crashes it. ------------------------------------------------------------------------ [2002-07-18 17:06:15] acs@hourglassone.com Looks like you're correct.. I added a trim() around the second paramater of split() and it seems to take care of it. It would seem that there's no checking done on the size parameter in php_split before calling add_next_index_stringl for the last value. line number is ext/standard/reg.c:574 in php4.2.2dev Snippet of code (offending line marked by >>>> <<<<), $sHeader is returned by curl_exec): class HeaderObj { function HeaderObj($sHeader) { $this->header = $sHeader; $aHeaders = Array(); >>>> $aLines = split("\n",$sHeader); <<<< foreach($aLines as $sLine) { $temp = split(":",trim($sLine)); $aHeaders[$temp[0]] = (isset($temp[1])) ? trim($temp[1]) : ""; if ($temp[0] == "Content-Type") { if (!isset($temp[1])) { $aHeaders[$temp[0]] = trim("text/html"); } } } if (!isset($aHeaders['Content-Type'])) { $aHeaders['Content-Type'] = "text/html"; } $this->headers = $aHeaders; $this->headers['string'] = $sHeader; reset($this->headers); } } --- If I put it in a trim(), with --enable-debug, I get this warning: <b>Warning</b>: String is not zero-terminated (HTTP/1.1 200 OK Date: Thu, 18 Jul 2002 20:58:13 GMT Server: Apache/1.3.23 (Unix) Last-Modified: Fri, 28 Jun 2002 23:00:30 GMT ETag: "736-3d1cea8e" Accept-Ranges: bytes Content-Length: 1846 Content-Type: application/x-javascript Toolbar=search; siteinfopopup=siteinfo; relatedlinkspopup=relatedlinks; twym=webyoumade; searchMethod=Yahoo; twym_disabled=false; ALXSID=ccd89a2e038361a7cb25c7f27130ed86; twym65=D4ABCAC7DEF19AA7979F60CED1A3%2521D7AED1C9EBED9CA59DA7A6DE9099A2E7%2521DB6C8FD3EBE1%2521C5ACD5C5E5DBAF9CA7AB9399C4A5ABA8A89D%2521D1B2D4D5E5A89CA2A1; aid=iKy4Z0eeh000NE Host: client.alexa.com:2222 Pragma: no-cache Accept: image/gif, image/x-xbitmap, image/jpeg, image/pjpeg, */* Referer: http://client.alexa.com/speed_test/index.html Accept-Language: en-us @) (source: zend_execute_API.c:274) in <b>Unknown</b> on line <b>0</b><br /> ------------------------------------------------------------------------ [2002-07-18 16:31:05] derick@php.net It crashes on a split function, can you try to shorten your script to narrow the search for us? Derick ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at http://bugs.php.net/18422 -- Edit this bug report at http://bugs.php.net/?id=18422&edit=1

« previous php.bugs (#19149) next »